[SRU][J][PATCH 1/1] inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP
Cengiz Can
cengiz.can at canonical.com
Fri Jun 26 19:27:02 UTC 2026
From: Eric Dumazet <edumazet at google.com>
Yizhou Zhao reported that simply having one RAW socket on protocol
IPPROTO_RAW (255) was dangerous.
socket(AF_INET, SOCK_RAW, 255);
A malicious incoming ICMP packet can set the protocol field to 255
and match this socket, leading to FNHE cache changes.
inner = IP(src="192.168.2.1", dst="8.8.8.8", proto=255)/Raw("TEST")
pkt = IP(src="192.168.1.1", dst="192.168.2.1")/ICMP(type=3, code=4, nexthopmtu=576)/inner
"man 7 raw" states:
A protocol of IPPROTO_RAW implies enabled IP_HDRINCL and is able
to send any IP protocol that is specified in the passed header.
Receiving of all IP protocols via IPPROTO_RAW is not possible
using raw sockets.
Make sure we drop these malicious packets.
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: Yizhou Zhao <zhaoyz24 at mails.tsinghua.edu.cn>
Link: https://lore.kernel.org/netdev/20251109134600.292125-1-zhaoyz24@mails.tsinghua.edu.cn/
Signed-off-by: Eric Dumazet <edumazet at google.com>
Reviewed-by: David Ahern <dsahern at kernel.org>
Reviewed-by: Ido Schimmel <idosch at nvidia.com>
Link: https://patch.msgid.link/20260203192509.682208-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba at kernel.org>
(backported from commit c89477ad79446867394360b29bb801010fc3ff22)
[bot_kybele: Kept dev_net() instead of upstream's dev_net_rcu() in the out:
stats line, since this tree predates the dev_net_rcu conversion and uses
dev_net() everywhere in icmp.c; the IPPROTO_RAW drop logic was applied as-is.]
CVE-2026-46266
Assisted-by: kybele:claude-opus-4.8
Signed-off-by: Cengiz Can <cengiz.can at canonical.com>
---
net/ipv6/icmp.c | 4 +++-
1 file changed, 3 insertions(+), 1 deletion(-)
diff --git a/net/ipv6/icmp.c b/net/ipv6/icmp.c
index ca13c540ab29..0c303a05fbbe 100644
--- a/net/ipv6/icmp.c
+++ b/net/ipv6/icmp.c
@@ -856,7 +856,9 @@ void icmpv6_notify(struct sk_buff *skb, u8 type, u8 code, __be32 info)
if (!pskb_may_pull(skb, inner_offset+8))
goto out;
- /* IPPROTO_RAW sockets are not supposed to receive anything. */
+ /* IPPROTO_RAW sockets are not supposed to receive anything.
+ * Add a more specific reason later ?
+ */
if (nexthdr == IPPROTO_RAW)
goto out;
--
2.43.0
More information about the kernel-team
mailing list