From: Aleksandr Khromov <haa@amicon.ru>
To: <dev@dpdk.org>
Cc: <thomas@monjalon.net>, <konstantin.ananyev@huawei.com>,
<olivier.matz@6wind.com>, <sdl.dpdk@linuxtesting.org>,
<rrv@amicon.ru>, <haa@amicon.ru>, <stable@dpdk.org>
Subject: [PATCH] net: fix signed shift overflow in IPv6 phdr cksum
Date: Fri, 18 Sep 2026 10:47:29 +0300 [thread overview]
Message-ID: <20260918074729.79205-1-haa@amicon.ru> (raw)
In rte_ipv6_phdr_cksum() the next header field, a uint8_t, is promoted to
a signed int before the left shift by 24. For protocol values >= 128
(for example IPPROTO_SCTP), proto << 24 does not fit in int, which is
undefined behaviour (signed left shift overflow) reported by UBSan:
rte_ip6.h: runtime error: left shift of 132 by 24 places cannot be
represented in type 'int'
Cast the operand to uint32_t before the shift so it is performed in
unsigned arithmetic. The resulting value is unchanged on two's
complement platforms. The same idiom is already used in RTE_IPV4().
Fixes: 6006818cfb26 ("net: new checksum functions")
Cc: stable@dpdk.org
Signed-off-by: Aleksandr Khromov <haa@amicon.ru>
---
.mailmap | 1 +
lib/net/rte_ip6.h | 2 +-
2 files changed, 2 insertions(+), 1 deletion(-)
diff --git a/.mailmap b/.mailmap
index 9e45cdce8f..2d55627dc5 100644
--- a/.mailmap
+++ b/.mailmap
@@ -46,6 +46,7 @@ Alan Liu <zaoxingliu@gmail.com>
Alan Winkowski <walan@marvell.com>
Alejandro Lucero <alejandro.lucero@netronome.com>
Aleksander Gajewski <aleksanderx.gajewski@intel.com>
+Aleksandr Khromov <haa@amicon.ru>
Aleksandr Loktionov <aleksandr.loktionov@intel.com>
Aleksandr Miloshenko <a.miloshenko@f5.com>
Aleksey Baulin <aleksey.baulin@gmail.com>
diff --git a/lib/net/rte_ip6.h b/lib/net/rte_ip6.h
index d1abf1f5d5..14e0101c14 100644
--- a/lib/net/rte_ip6.h
+++ b/lib/net/rte_ip6.h
@@ -566,7 +566,7 @@ rte_ipv6_phdr_cksum(const struct rte_ipv6_hdr *ipv6_hdr, uint64_t ol_flags)
rte_be32_t proto; /* L4 protocol - top 3 bytes must be zero */
} psd_hdr;
- psd_hdr.proto = (uint32_t)(ipv6_hdr->proto << 24);
+ psd_hdr.proto = (uint32_t)ipv6_hdr->proto << 24;
if (ol_flags & (RTE_MBUF_F_TX_TCP_SEG | RTE_MBUF_F_TX_UDP_SEG))
psd_hdr.len = 0;
else
--
2.48.1
next reply other threads:[~2026-09-19 8:17 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-18 7:47 Aleksandr Khromov [this message]
2026-09-21 21:15 ` [PATCH] net: fix signed shift overflow in IPv6 phdr cksum Stephen Hemminger
2026-09-28 14:18 ` Thomas Monjalon
2026-09-29 7:21 ` Aleksandr Khromov
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260918074729.79205-1-haa@amicon.ru \
--to=haa@amicon.ru \
--cc=dev@dpdk.org \
--cc=konstantin.ananyev@huawei.com \
--cc=olivier.matz@6wind.com \
--cc=rrv@amicon.ru \
--cc=sdl.dpdk@linuxtesting.org \
--cc=stable@dpdk.org \
--cc=thomas@monjalon.net \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.