Executive brief
A race condition vulnerability was identified in the Linux kernel's networking subsystem, specifically affecting how the system handles secure IP (IPsec) traffic and error messages. Under specific timing conditions, such as when a network address is added while the system is processing an error message, the kernel can encounter an internal inconsistency. This results in a system warning and potential instability in network routing, though it primarily impacts system reliability rather than direct data exposure.
Technical details
A race condition exists in the icmp_route_lookup() function within the Linux kernel's XFRM (IPsec) subsystem. When the kernel is a forwarding node and performs a reverse path lookup for an ICMP error message, it calls ip_route_input(). If the destination address (the original packet's source) is concurrently added as a local address (e.g., via 'ip addr add'), ip_route_input() may return a LOCAL route with the output handler set to ip_rt_bug(). Subsequent attempts to use this route for ICMP output trigger a WARN_ON in net/ipv4/route.c. The fix involves verifying that the returned route type is not RTN_LOCAL before proceeding with the output.
Affected products
- Linux Linux kernel Fixed in 6.1.x, 6.6.x, 6.12.x, 6.13.x, and 6.14+
Timeline
- 2026-02-06: patched: Initial fix authored by Jiayuan Chen
- 2026-05-27: advisory: CVE-2026-45905 published by NVD
References
- https://git.kernel.org/stable/c/1c9ef28f643cce34a6a6c36c8f4d6d60a60db7e1
- https://git.kernel.org/stable/c/2c1f59005da9dd4b07b26984fd719e36557dc57c
- https://git.kernel.org/stable/c/423ce12d10b426709489d6b84fdaa6d2f31c5652
- https://git.kernel.org/stable/c/81b84de32bb27ae1ae2eb9acf0420e9d0d14bf00
- https://git.kernel.org/stable/c/9a95ec9144eeff1fc6fbcc21b677e322c6f1430b
- https://git.kernel.org/stable/c/b04061f89ffc6168e7ec3c71d0086ec3c3797228