From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 87EC433A6F1; Wed, 30 Sep 2026 19:10:50 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790795451; cv=none; b=MJlFND3sTPgi6beUEXZL0e3AXqBh6jwRNXyKIq2S7Cd9+tcYg40x5ZE0dJkYCACVD45TVQWs596jxM5PjR+FabJDsoC9VFpMBUPb1rnU2oOxL/g0gwLTrN0BIfeebWjzTHfNY91BGvD8EGOklq3DdxS7qcLyKqWKRBSZpH3ecJc= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790795451; c=relaxed/simple; bh=qyrdsJOU07/KQsXquQzR4EPj8KIth1gSGBHE7IeeNYo=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=brqcN8YL8+hlWuEnkx24XIrBS+3QOmSYpr3zbh6nd4cJRFBh9zXS/Tx1q7wEIKcFLZnfZ4f3qsc7qzgO7IYmn3VVG/6OZPPFV4MLIVI+SsRREq3UkViMdil5GAuCO1b1Ghw/4qnHfokBwm2DTDwYTUhHyZyTFrdnJbM/NtMMvnE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=Z+gxXych; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="Z+gxXych" Received: by smtp.kernel.org (Postfix) with ESMTPSA id E361E1F000FF; Wed, 30 Sep 2026 19:10:49 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790795450; bh=np8Lv0p0wfgARfijhwj7JRA6JTyJOLw5HIvK+oyVVxk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=Z+gxXych/YCKJkDSTTPO/6R+oy8sqjnHT9p2jnXBJeiMVVjjTBx9r9Y6SFfw4Srhj UvDWNxRMN4xCD0CYmp++w8A7L2PaVs68ctsfwjA4io7pfVSDZiYQqVoZzMXP1DR2dn fs4sdtEAN0fYHC7+l8FnHOY/TsANlnteBtMo8n9M= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Zhiling Zou , Florian Westphal , Pablo Neira Ayuso , Sasha Levin Subject: [PATCH 6.6 0521/1193] netfilter: ip6_tables: set F_PROTO when proto value is nonzero Date: Wed, 30 Sep 2026 17:20:05 +0200 Message-ID: <20260930152445.758788590@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152434.301151190@linuxfoundation.org> References: <20260930152434.301151190@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.6-stable review patch. If anyone has any objections, please let me know. ------------------ From: Florian Westphal [ Upstream commit da4afc5a956d407443988e97a4d4ca14c2e999c7 ] The ip6tables traverser doesn't search the extension header chain unless userspace did set the IP6T_F_PROTO flag. This also means that userspace that sets the e->ipv6.proto flag can bypass the protocol check for the rule by not setting this flag. That in turn means that all ip6_tables modules and targets that want to reject rules without '-p' flag MUST also check for that flag. Not all do, likely because they got copied from iptables which lacks this flag (no extension headers). Instead of fixing up all the relevant targets, emulate ip6tables behaviour in the kernel (like nft_compat.c) and set the flag if the protocol is set. Reported-by: Zhiling Zou Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Signed-off-by: Florian Westphal Signed-off-by: Pablo Neira Ayuso Signed-off-by: Sasha Levin --- net/ipv6/netfilter/ip6_tables.c | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/net/ipv6/netfilter/ip6_tables.c b/net/ipv6/netfilter/ip6_tables.c index 858cea15e322f..3f08d4600d696 100644 --- a/net/ipv6/netfilter/ip6_tables.c +++ b/net/ipv6/netfilter/ip6_tables.c @@ -647,6 +647,11 @@ check_entry_size_and_hooks(struct ip6t_entry *e, /* Clear counters and comefrom */ e->counters = ((struct xt_counters) { 0, 0 }); e->comefrom = 0; + + /* set F_PROTO, else ip6_packet_match won't do the right thing. */ + if (e->ipv6.proto) + e->ipv6.flags |= IP6T_F_PROTO; + return 0; } -- 2.53.0