From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qt1-f172.google.com (mail-qt1-f172.google.com [209.85.160.172]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 8ED0729A31C for ; Mon, 10 Aug 2026 15:47:34 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.160.172 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786376857; cv=none; b=uvjuRRUmIbJ9jFFPYu8AWkziw92UC0tNDyDnKXiMB9Du2zf4wLgNrvUz+0yJqfCd4pMp5mv5hbNr5MuAJ9y622RtqyU5NTgL+fpX0cEXtMlJ3OLIPMog/cXLeZDCMPOSPnKS0wEk89rPugFKYeBQfjML8GlHOS3B5kSeOZq9epU= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1786376857; c=relaxed/simple; bh=wOmW7m7NE03gMf7iUofQ0pKee8XEwyElqjWYwIQXPWE=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=c5XIf7w6SbLHbVH5xWDRfOWzQNqA5w4/4R/yn5zK7WRxHGnoMb2AoxQgllXo3B8BrOI2FjL96YPr60ikrFw5vbw/aZdPWCzThSptbGza2qwsPhE05lhDQ9ny96kCdHK9cNmH8ZhXXudUMGV8u4Ecy70Yz6sBjEKqx2sUQr3wQGQ= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=KIQi8RyJ; arc=none smtp.client-ip=209.85.160.172 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="KIQi8RyJ" Received: by mail-qt1-f172.google.com with SMTP id d75a77b69052e-51c928bf172so13008111cf.3 for ; Mon, 10 Aug 2026 08:47:34 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1786376853; x=1786981653; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=cz2j7Ub+YNraWKHWXqt2U9IfnVOCLgD0ZKsDhgeBKYo=; b=KIQi8RyJZxiiVqMbzgtZzFkUc8jPDiwIasq+ZTX3ZLxiC9qhjZqifarfla7u+Nk66W pcVkHOnO6fUPtXHEuFdcA2mkW+NtQfVnI+IuANhS5XEKqVxIP3iacugjNeZejOAtvT96 J5MwH6cMUCCOcmo6r930pJgSsf8T2bYuqGdYL0jfiRjK7LigWj002AAqUxhKHIEPboqa Ihf+Ak3RKDcqovtqeZuuyzH+4P8EseWWWMv5Q5mofGXq4QsfwHPr4d4L3Y4Uld3Cl2Lr jyWWLfJQVumkDCSsvXfMYhixwipIsZqm21S4ZpO4k0Pdk+koei2/eua+OXaL5HRhImGz GY+w== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1786376853; x=1786981653; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=cz2j7Ub+YNraWKHWXqt2U9IfnVOCLgD0ZKsDhgeBKYo=; b=HuLxDtnjRIdM5gevMsE05CQ76s/IYw5jNgAG62UmmDsSKBpioZrqApqf5IeFG2RBJG j1KcVu9HQ809G7TmpE3Ei+m52qjqr5OcALwLyPFaMDfbuGT+KTagNL/GgPAmIxIq/lQg 6B9GBGufzOFTetCvomxwUajCMTqLKsRLp7EcpxG830OSIOSCPQT2nXhkSj/2xac2IzHP SvAw7aJpzpqjUGlhu9BDAF80oX7ddesdDLl2ZV4pCG+z7WEHADZc8twpBOZcak/dgvCv 5OSJyNY0zjMRwteqiSBQmaM0ohr0GICW6gVSNsuFTz6AHsu+aaQO5/pei4YQqY5X/nei qoDg== X-Forwarded-Encrypted: i=1; AHgh+RpaDqobL3dDnRR4TWDjMGYplyPtrsqkMc2504b1nqWJTMIICDwfMo+ff2owZMD+SuxPKWJqGGdQQh6ZwgQ=@vger.kernel.org X-Gm-Message-State: AOJu0YxmJQZknCxLlmEp17WSmlMsN2pkhMzXUzRZ1k0FbNR1yfp2t19L ru/q/Chrgyxn59SFeL1JO3qLUJw00MnqmFcvXPHiOeaPwcEE80s7bTFnS/hdxCxfuZA= X-Gm-Gg: AR+sD12iVy8m8Xibjpmf1iy34ekRd4fSkZLjt3Hu6pljIAI3487R5ts4OCW1frZnIQ5 PkuajRTOjP3ztJ0c6GQEuLHT6mNF9/f8O/mHy5pYGo+Ey6waBHrvSQE5+LNqFxga6a8lx9ulbhe d0K+PFeZSKg+XzX5DnCSSFX1xMm81s3e0UOvW1o0hl7xLdgvlYZwCjHYD02IO/NRtH3gZPowLLe MxhJbUHD0K3gJ/MoHuE0LMoU6NOEMqo0/GMZKYloCrEUp931HikhfRDLpuMzHLd44crbS+JFw5V AlXu4Hr21J++YpJ97UhaiOXsOzgvWfyQUS7VIjtNbGd9ERyRAElJIpFToprdn+ppMez2vDLqGta VMkrISMlL2daKksS4t1UFo0+3PkbJbgogD1hPifWTkN9uPezmLNbrS5kYmhg1zn3/DOkiAbfbHN /2RZwnSo9HjZ4tYlpTZBHmgLRseqei2d1hqEaeED23uafXqQMZGxKu2D0IqrdYIaKpVw== X-Received: by 2002:ac8:5ad3:0:b0:51b:fb4f:afdf with SMTP id d75a77b69052e-52ce5f612dbmr458618171cf.9.1786376853398; Mon, 10 Aug 2026 08:47:33 -0700 (PDT) Received: from localhost ([146.190.222.192]) by smtp.gmail.com with UTF8SMTPSA id d75a77b69052e-52d1637f4a1sm74972291cf.9.2026.08.10.08.47.32 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 10 Aug 2026 08:47:33 -0700 (PDT) From: David Lee To: andrea.mayer@uniroma2.it, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com Cc: Kyle Zeng , Dominik 'Disconnect3d' Czarnota , Nicolas Dichtel , horms@kernel.org, stefano.salsano@uniroma2.it, dsahern@kernel.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, David Lee Subject: [PATCH net v3] ipv6: seg6: clear IPv4 control block on IPIP decapsulation Date: Mon, 10 Aug 2026 15:47:31 +0000 Message-ID: <20260810154732.850472-1-david.lee@trailofbits.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Kyle Zeng End.DX4 and End.DT4 decapsulate an IPv4 packet through decap_and_validate() and send it directly to IPv4 routing. The inner packet therefore bypasses ip_rcv_core(), which normally clears IPCB before IPv4 interprets skb->cb. The skb instead retains IP6CB data from the outer packet. IPv6 extension-header offsets overlap IPv4 option fields, so IPv4 can treat those offsets as saved option metadata. __ip_options_echo() can then copy beyond the allocation for saved options. Separate End.DX4 and End.DT4 reproducers on the unpatched v7.2-rc5 kernel both produced: BUG: KASAN: slab-out-of-bounds in __ip_options_echo() Write of size 255 The End.DX4 trace passes through input_action_end_dx4_finish() and input_action_end_dx4(), while the End.DT4 trace passes through input_action_end_dt4(). When decap_and_validate() handles IPPROTO_IPIP, save the ingress interface from IP6CB, clear IPCB, and restore the saved value. Doing this in the common decapsulation path covers End.DX4, End.DT4, and End.DT46's IPv4 arm. Use IP6CB(skb)->iif rather than skb->skb_iif. These actions run after l3mdev processing, which can replace skb_iif with the L3 master; IP6CB iif still records the receiving interface set at IPv6 ingress. Fixes: 891ef8dd2a8d ("ipv6: sr: implement additional seg6local actions") Cc: stable@vger.kernel.org Suggested-by: Andrea Mayer Assisted-by: Codex:gpt-5.6-sol Codex:gpt-5.5-cyber Signed-off-by: Kyle Zeng Co-developed-by: David Lee Signed-off-by: David Lee --- Changes in v3: - Clear IPCB in the common IPPROTO_IPIP decapsulation path so End.DX4, End.DT4, and End.DT46's IPv4 arm are covered. - Preserve the ingress interface from IP6CB instead of skb->skb_iif, which can identify the VRF master after l3mdev processing. - Update the Fixes tag to the commit that introduced End.DX4. - Include the End.DX4 and End.DT4 KASAN evidence. v2: https://lore.kernel.org/netdev/20260804094625.715305-1-david.lee@trailofbits.com/ v1: https://lore.kernel.org/all/20260731140832.567669-1-david.lee@trailofbits.com/ net/ipv6/seg6_local.c | 7 +++++++ 1 file changed, 7 insertions(+) diff --git a/net/ipv6/seg6_local.c b/net/ipv6/seg6_local.c index 2b41e4c0dddd..95ea0b62729a 100644 --- a/net/ipv6/seg6_local.c +++ b/net/ipv6/seg6_local.c @@ -256,6 +256,13 @@ static bool decap_and_validate(struct sk_buff *skb, int proto) if (iptunnel_pull_offloads(skb)) return false; + if (proto == IPPROTO_IPIP) { + int iif = IP6CB(skb)->iif; + + memset(IPCB(skb), 0, sizeof(*IPCB(skb))); + IPCB(skb)->iif = iif; + } + return true; } -- 2.53.0