From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 362D851476F; Wed, 30 Sep 2026 17:24:59 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789100; cv=none; b=HSzPClMqTKysiHhIYimdsb0rsXsAgICIogOCAhmIdSIyjzY5sQwkoXos4u2nwDurkrZEYMmyVb5MTPXSWJFx/4Y+SqQnpfx1itliFgv+lmI5Ahk3/9UmK0+wxk85rV23U0l1mBeadEMGEt9v9PZDJ1+POA9z0fIYzJwE0p89BlE= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790789100; c=relaxed/simple; bh=/+bhkBZ8vwvF2Md+vHy6IlQk9NcP0vg1CowHXOyV6tU=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=DqFvt/3YPoMAyEKj/o1LOlKIsX+vi//bmMDK20kBNcCazoS9m3N1DiePG4nNsngFV5gZ46bC89+4g188RhjTEokmFbKJBo7OtITiwpvG7O6lhDtnSxYlNrL44lPp1jh2YM57Dg5GihgF9J1qflcaHB4vkksCf3q9FATM4RxVAb4= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=GtEl7Iwh; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="GtEl7Iwh" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 5B52A1F000FF; Wed, 30 Sep 2026 17:24:58 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790789098; bh=2+UZFkZ6U0j8eEpMGEZEX/Y61PGqp2oVYhOCSqzUFK8=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=GtEl7IwhDEZIVZDd30yTgJkQ4eVYWBcuulZQb7sCCFGkfxDRG/jlNxmifjmZH7gLC mCRsrQnzNqEtJWoJFqaLOxb2I78jqeHKagKkhggQcKXKx5J93eKU1+RuVu9vuQJMwp SCRxlcmpCcMWI0RS9hYqSJr2+08U6GmW7GW/VXU0= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Julian Anastasov , Pablo Neira Ayuso , Sasha Levin Subject: [PATCH 6.12 351/877] ipvs: revalidate ihl before icmp_send Date: Wed, 30 Sep 2026 17:21:02 +0200 Message-ID: <20260930152422.246996629@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Julian Anastasov [ Upstream commit e290145564886d6a3038810c621f738c1fe9fa51 ] While the outer IP header is already pulled into the skb head, we must be careful and revalidate the embedded headers after reading them from the skb frags to prevent possible out-of-bounds access. One such place reported by Sashiko is ip_vs_in_icmp() where local process can change the ihl field and after pskb_may_pull() we can see larger value. Even if icmp_send() has checks to prevent out-of-bounds access, play safe and add check to drop the packet if the ihl field is changed. As the outer headers are pulled, make sure the transport header is updated too, it was used before commit 7fcc2fe39fed ("net: icmp: avoid invalid transport header access in icmp_send tracepoint") Fixes: f2edb9f7706d ("ipvs: implement passive PMTUD for IPIP packets") Link: https://sashiko.dev/#/patchset/20260806105211.34622-1-ja%40ssi.bg Signed-off-by: Julian Anastasov Signed-off-by: Pablo Neira Ayuso Signed-off-by: Sasha Levin --- net/netfilter/ipvs/ip_vs_core.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/net/netfilter/ipvs/ip_vs_core.c b/net/netfilter/ipvs/ip_vs_core.c index 1f62ca2f73309..4e30a903f4bdc 100644 --- a/net/netfilter/ipvs/ip_vs_core.c +++ b/net/netfilter/ipvs/ip_vs_core.c @@ -1776,6 +1776,12 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related, /* Ensure the IP header is present in headroom */ if (!pskb_may_pull(skb, hlen_orig)) goto ignore_tunnel; + skb_set_transport_header(skb, hlen_orig); + /* Before now we may used ihl from skb frag, revalidate it after + * copying it into skb head to prevent out-of-bounds access + */ + if (ip_hdr(skb)->ihl * 4 != hlen_orig) + goto ignore_tunnel; IP_VS_DBG(12, "Sending ICMP for %pI4->%pI4: t=%u, c=%u, i=%u\n", &ip_hdr(skb)->saddr, &ip_hdr(skb)->daddr, type, code, ntohl(info)); -- 2.53.0