ACK: [SRU][J][PATCH 0/1] CVE-2026-46266

Kuba Pawlak kuba.pawlak at canonical.com
Thu Jun 25 10:11:29 UTC 2026


On 6/24/26 02:23, Cengiz Can via kernel-team wrote:
> https://ubuntu.com/security/CVE-2026-46266
>
> [ Impact ]
>
> A RAW socket opened on protocol IPPROTO_RAW (255) incorrectly matches incoming
> ICMP error packets whose embedded inner header carries protocol 255. A
> malicious ICMP packet (for example type 3, code 4) can therefore reach such a
> socket and trigger FNHE (forwarding next hop exception) cache changes in the
> routing layer. Per "man 7 raw", receiving of IP protocols via IPPROTO_RAW is
> not supposed to be possible, so these packets must be dropped rather than
> delivered.
>
> [ Fix ]
>
> jammy: backported with AI-assisted adaptation
> focal: backported with AI-assisted adaptation
>
> [ Test Plan ]
>
> Boot tested.
>
> [ Where Problems Could Occur ]
>
> If the fix is incorrect, it could affect delivery of legitimate traffic to RAW
> sockets in the IPv4 input path, or alter ICMP error handling and routing
> exception (FNHE) behavior in the inet subsystem.
>
Acked-by: Kuba Pawlak <kuba.pawlak at canonical.com>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_0x216A9D7E3B63DCB4.asc
Type: application/pgp-keys
Size: 3139 bytes
Desc: OpenPGP public key
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20260625/09fa25c6/attachment.key>
-------------- next part --------------
A non-text attachment was scrubbed...
Name: OpenPGP_signature.asc
Type: application/pgp-signature
Size: 840 bytes
Desc: OpenPGP digital signature
URL: <https://lists.ubuntu.com/archives/kernel-team/attachments/20260625/09fa25c6/attachment.sig>


More information about the kernel-team mailing list