From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id E80294E4304; Wed, 30 Sep 2026 16:20:42 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790785247; cv=none; b=qtW3m6t9tRz5iZSBvdXQxDuliqy5RmJdZxLTp3PoXa0wGdy2ECfUO0VZtSCCbwSd8KTnm+Y7KBU5R+EgLchdn3aiwoA63n1XD4qgri0k4Z5dRLqZErVcZ0I8oe1AVJLM7mDSkZ2x4kgissjgnj23apN+U3mdGrvnN9JsoRniCD8= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790785247; c=relaxed/simple; bh=dsdvRnT46HLbFR+BBazbWAVkmU0Q/r5nk1KKz9YKlWk=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=Nw1p9QLOuRthiiuPIJwqUHxXPWO0aAbHrhWsSZ2SuUu2KL8nRfxJP++FGOLvD3xuzArgDPpHodVP39u/Cp4h5jSneeMFR/262q0JbmFcz6Y+3ZGrhG67RT/SnfktRiVuwZEomE//Ijhmwi84f3PhmmJxiwh0JGlmjoWdnsXuZdY= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=l994HtPF; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="l994HtPF" Received: by smtp.kernel.org (Postfix) with ESMTPSA id A3B9C1F00893; Wed, 30 Sep 2026 16:20:39 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790785240; bh=bWL2qvckrAI6qnvVK37W4Qc70Xpct6ZPS4HppywlJj0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=l994HtPFuZFTBqLht+aVMoYIDvSwm6IntyA2ngCBv8lwwXiBbuGi1aORghg4JBANG tv3q0Khk+snfh7QW9ATjImCDtdujo9Ze6CR7crfw6jeNF4d4E2jE0obZ4wZVv+jn91 xkUDmJ4Xze2CBImPDIuzduT39xjuF/LEF22J3fiw= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Zhiling Zou , Florian Westphal , Pablo Neira Ayuso , Sasha Levin Subject: [PATCH 6.1 437/982] netfilter: ip6_tables: set F_PROTO when proto value is nonzero Date: Wed, 30 Sep 2026 17:19:33 +0200 Message-ID: <20260930152426.181203733@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152416.775402466@linuxfoundation.org> References: <20260930152416.775402466@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.1-stable review patch. If anyone has any objections, please let me know. ------------------ From: Florian Westphal [ Upstream commit da4afc5a956d407443988e97a4d4ca14c2e999c7 ] The ip6tables traverser doesn't search the extension header chain unless userspace did set the IP6T_F_PROTO flag. This also means that userspace that sets the e->ipv6.proto flag can bypass the protocol check for the rule by not setting this flag. That in turn means that all ip6_tables modules and targets that want to reject rules without '-p' flag MUST also check for that flag. Not all do, likely because they got copied from iptables which lacks this flag (no extension headers). Instead of fixing up all the relevant targets, emulate ip6tables behaviour in the kernel (like nft_compat.c) and set the flag if the protocol is set. Reported-by: Zhiling Zou Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Signed-off-by: Florian Westphal Signed-off-by: Pablo Neira Ayuso Signed-off-by: Sasha Levin --- net/ipv6/netfilter/ip6_tables.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/net/ipv6/netfilter/ip6_tables.c b/net/ipv6/netfilter/ip6_tables.c index 333115dff69ae..ad559d4a877a3 100644 --- a/net/ipv6/netfilter/ip6_tables.c +++ b/net/ipv6/netfilter/ip6_tables.c @@ -649,6 +649,11 @@ check_entry_size_and_hooks(struct ip6t_entry *e, /* Clear counters and comefrom */ e->counters = ((struct xt_counters) { 0, 0 }); e->comefrom = 0; + + /* set F_PROTO, else ip6_packet_match won't do the right thing. */ + if (e->ipv6.proto) + e->ipv6.flags |= IP6T_F_PROTO; + return 0; } -- 2.53.0