From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pl1-f170.google.com (mail-pl1-f170.google.com [209.85.214.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A2AAD3054C7 for ; Wed, 29 Jul 2026 03:48:10 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.214.170 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785296892; cv=none; b=GlJqmL1g5lFBVXLBR0yi5Aby7zH5sloc4npLDHmldQsFi9JP+cN6iwJht0HAcMb1aeXrJWuVHnu5WZjAhYKO3VY8AcEZ1kjcAVo/UUJwt/CniscR56keqjTlgjrjnyRFhRoOHK2WTVTIQ/mTOI5OnH2frX/XPIiolKNRFukV3lg= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785296892; c=relaxed/simple; bh=P9nGJR3wq037sbZ4BCSnVggh+4PFS3z4B0EBS37VO8g=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=rZzcD1EPThq/yoP7Ex7ckhEdnFbyAsWHA+/25umnuRS3X6AJyzYudtv6yt4O74tE5K/yEeVFkHZ/fUD2sy/hafO7tuTGO5p6Qky9TksBYxZxHvUsozRP5vEm+SZWd62WsNBw9ifGrdRq81WKpjRHyfvkIpIqAuyDsPWtAAV68wE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=mIQ65k8/; arc=none smtp.client-ip=209.85.214.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="mIQ65k8/" Received: by mail-pl1-f170.google.com with SMTP id d9443c01a7336-2ce7d2adef4so8063695ad.3 for ; Tue, 28 Jul 2026 20:48:10 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785296890; x=1785901690; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=j4mXarqLChjkLTj7P6sDrdVZlpiC+6o8xzReS9GjIp0=; b=mIQ65k8/ChweQkNT0a0PXC6I5OSBPAEofmc665+CgmRnfXELV1iNhpmjNH1qLF82fF qLMSNNQzcwnGONLuiwxBZk3V5n3vlRAy7azeqPSq1th890LyhLqMS1hvZ7fYIf8iPXIT e9gczM6Io75ZCIQvloUJWuMSQBcV7gs4xDnvH7LTH6AIxNcG8VVMyKqZuU64vMl7M7bN 2aRvIvZaBsM+yzUY+56DIEdfmPTXon7xsqL3OsGxpIlygwhDG7sU41u/0CE7JlvTHQcb YetRHpV/UiEBKl9RAVjKUwejO/GuzlbDWa9cl74JmroWXGzNfYqcGQZoZ5xZzaeElXpz VSjA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785296890; x=1785901690; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=j4mXarqLChjkLTj7P6sDrdVZlpiC+6o8xzReS9GjIp0=; b=D3Qthzx18yZzBaQMoiL808wrP7sS5c3JLaHywPaXoXhfcScFFfZN9adBseKOu866q9 9zWCPCRUsMBzxlQ05nPbIGiAK84FuWTJuxUWFsQpcH+j1o5GSdZMQUr7G4aSP0CU9N9h s4WBgMiTP9PJNL+vKXgZs71CTnxJD6tEeMlhMRgOiyWjz/LETI44UuGruL+Z4JsnEg7u r4pT1LouRe2U3DySGJXzgXOCXOi7JXFcIl0VBSNdhD5wy8IzCFTGMYISragRWy3tY0Uv 9uMbsHRPnViBXupQI+tzlrZ9YTtBVso/qqfJJ5xlTjYaw123hVsU8f/hRTqb3Eke0UP0 1EBg== X-Forwarded-Encrypted: i=1; AHgh+RrVrK66umOvGUd09RFpWUz7W8+ckR+ogasW5pIE3TQUpvliE1J5bjXfnXjIXJbykEAA6gv1r/cGX+/azLA=@vger.kernel.org X-Gm-Message-State: AOJu0Yxrni/6ljJ1B1KvMe0XapH1gSI0RogzBzot8q4ouhr0mdT2T6/f sWWjw8gtqHQ6OP5+eIZzOqgHSNWLMwfIu086eHPaG6ebLyT6Qz1YHU7q X-Gm-Gg: AR+sD10AUe1TF869vzWWP2/pGnkhVKZ8LlKWsGzoFmFUW39JDuiVKgo5cuyJwvNE7kC tP+JbUc6VFkFmUWmfcaHUVChlcJNUMEip9gUy3Y1/sFU2yFjw/ICeiIhPlQMWQ8DHWeRZFapPJV jJ/Z23iJaPzA02n6AE/bKouU0D1bcndshSmKflrhZAU2kBHF1GP8348trC9GrNZu5fVXs8GTavx 4JVjfv0y1E0JFxBMfkIGDr5SJdNSRZeXTTwYbUsQRyVKGXAY5hIgkHoueI4kOHNoK+4J1WOhHxn 1xiUWREQ/ZzmIYUYVDXM/Z0L2lQrVlBS8TdcGbB43rvqh3nulJHjZUV4i1TFNtQlYMw2KXz4qe3 i9cXoAvuBY6NkFIImY8feEOsDAWl/CpiTlwcdrMe5WMWMMTMJ7xBArHgG9muVsrQ/DtjSKb7hXT YpxI/oEE/5bNBGgT6SB5uW1p6bY5kxQrxv2HTax++Ion8gXbHPtn/kc0y82MUJ6rRv8b03KPunv D7+F060vw== X-Received: by 2002:a17:903:3c68:b0:2cc:ffa6:4622 with SMTP id d9443c01a7336-2d016052725mr68562065ad.41.1785296890050; Tue, 28 Jul 2026 20:48:10 -0700 (PDT) Received: from localhost.localdomain ([116.105.227.66]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2d022a15215sm4544985ad.8.2026.07.28.20.48.06 (version=TLS1_3 cipher=TLS_CHACHA20_POLY1305_SHA256 bits=256/256); Tue, 28 Jul 2026 20:48:09 -0700 (PDT) From: Yuejie Shi To: David Ahern , Ido Schimmel , "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni Cc: Simon Horman , YOSHIFUJI Hideaki , netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org Subject: [PATCH net] ipv6: fix Route Information option length validation Date: Wed, 29 Jul 2026 11:47:19 +0800 Message-ID: <20260729034806.58923-1-syjcnss@gmail.com> X-Mailer: git-send-email 2.50.1 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit rt6_route_rcv() validates the Route Information option (RFC 4191) length against the prefix length, but both checks are off by one. rinfo->length is the ND option length in units of 8 octets and it *includes* the 8-byte option header, so an option carrying N bytes of prefix has length == 1 + N/8. RFC 4191 section 2.3 requires length 3 when Prefix Length is greater than 64, and 2 or 3 when it is greater than 0. The code accepts length >= 2 and length >= 1 respectively. ipv6_addr_prefix() then copies prefix_len/8 bytes out of rinfo->prefix, so a Router Advertisement with (prefix_len=128, length=2) or (prefix_len=64, length=1) makes the kernel read up to 8 bytes past the end of the option. Those bytes end up in the prefix of the route that gets installed, so they are visible to userspace: # RA with a Route Information option (prefix_len=128, length=2) # followed by a source link-layer address option, 01 01 de ad be ef ca fe $ ip -6 route show 2001:db8:dead:beef:101:dead:beef:cafe via fe80::1234 dev veth0 proto ra ^^^^^^^^^^^^^^^^^^ the next option, read out of bounds When the Route Information option is the last one in the packet, those eight bytes come from the skb tail room instead. Reject the option lengths RFC 4191 does not allow. Fixes: 70ceb4f53929 ("[IPV6]: ROUTE: Add experimental support for Route Information Option in RA (RFC4191).") Cc: stable@vger.kernel.org Signed-off-by: Yuejie Shi --- net/ipv6/route.c | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/net/ipv6/route.c b/net/ipv6/route.c index fc42d67e5822..5968ce5ad150 100644 --- a/net/ipv6/route.c +++ b/net/ipv6/route.c @@ -988,13 +988,13 @@ int rt6_route_rcv(struct net_device *dev, u8 *opt, int len, } else if (rinfo->prefix_len > 128) { return -EINVAL; } else if (rinfo->prefix_len > 64) { - if (rinfo->length < 2) { + /* RFC 4191: Length MUST be 3 when Prefix Length > 64 */ + if (rinfo->length < 3) return -EINVAL; - } } else if (rinfo->prefix_len > 0) { - if (rinfo->length < 1) { + /* RFC 4191: Length MUST be 2 or 3 when Prefix Length > 0 */ + if (rinfo->length < 2) return -EINVAL; - } } pref = rinfo->route_pref; -- 2.51.0