[SRU][J][PATCH 1/1] inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP

Cengiz Can cengiz.can at canonical.com
Fri Jun 26 19:27:02 UTC 2026


From: Eric Dumazet <edumazet at google.com>

Yizhou Zhao reported that simply having one RAW socket on protocol
IPPROTO_RAW (255) was dangerous.

  socket(AF_INET, SOCK_RAW, 255);

A malicious incoming ICMP packet can set the protocol field to 255
and match this socket, leading to FNHE cache changes.

inner = IP(src="192.168.2.1", dst="8.8.8.8", proto=255)/Raw("TEST")
pkt = IP(src="192.168.1.1", dst="192.168.2.1")/ICMP(type=3, code=4, nexthopmtu=576)/inner

"man 7 raw" states:

  A protocol of IPPROTO_RAW implies enabled IP_HDRINCL and is able
  to send any IP protocol that is specified in the passed header.
  Receiving of all IP protocols via IPPROTO_RAW is not possible
  using raw sockets.

Make sure we drop these malicious packets.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Yizhou Zhao <zhaoyz24 at mails.tsinghua.edu.cn>
Link: https://lore.kernel.org/netdev/20251109134600.292125-1-zhaoyz24@mails.tsinghua.edu.cn/
Signed-off-by: Eric Dumazet <edumazet at google.com>
Reviewed-by: David Ahern <dsahern at kernel.org>
Reviewed-by: Ido Schimmel <idosch at nvidia.com>
Link: https://patch.msgid.link/20260203192509.682208-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba at kernel.org>
(backported from commit c89477ad79446867394360b29bb801010fc3ff22)
[bot_kybele: Kept dev_net() instead of upstream's dev_net_rcu() in the out:
 stats line, since this tree predates the dev_net_rcu conversion and uses
 dev_net() everywhere in icmp.c; the IPPROTO_RAW drop logic was applied as-is.]
CVE-2026-46266
Assisted-by: kybele:claude-opus-4.8
Signed-off-by: Cengiz Can <cengiz.can at canonical.com>
---
 net/ipv6/icmp.c | 4 +++-
 1 file changed, 3 insertions(+), 1 deletion(-)

diff --git a/net/ipv6/icmp.c b/net/ipv6/icmp.c
index ca13c540ab29..0c303a05fbbe 100644
--- a/net/ipv6/icmp.c
+++ b/net/ipv6/icmp.c
@@ -856,7 +856,9 @@ void icmpv6_notify(struct sk_buff *skb, u8 type, u8 code, __be32 info)
 	if (!pskb_may_pull(skb, inner_offset+8))
 		goto out;
 
-	/* IPPROTO_RAW sockets are not supposed to receive anything. */
+	/* IPPROTO_RAW sockets are not supposed to receive anything.
+	 * Add a more specific reason later ?
+	 */
 	if (nexthdr == IPPROTO_RAW)
 		goto out;
 
-- 
2.43.0




More information about the kernel-team mailing list