Netdev List
 help / color / mirror / Atom feed
* [PATCH net] netfilter: nf_conntrack_reasm: avoid truncating header offset
@ 2026-09-29  9:00 tjdqudcks0424
  2026-09-29  9:14 ` netdev-bot+sinfo
                   ` (2 more replies)
  0 siblings, 3 replies; 6+ messages in thread
From: tjdqudcks0424 @ 2026-09-29  9:00 UTC (permalink / raw)
  To: netfilter-devel; +Cc: pablo, fw, phil, netdev, 성병찬, stable

From: 성병찬 <tjdqudcks0424@naver.com>

find_prev_fhdr() stores the offset of the previous Next Header field in
an 8-bit variable. A valid IPv6 extension header chain can place that
field at offset 256, causing the value to wrap to zero.

The truncated value is later stored in frag_queue.nhoffset and used by
nf_ct_frag6_reasm() as the index at which the Fragment Header's next
header value is written. With an offset of 256, this overwrites byte
zero of the IPv6 header instead of the preceding extension header's
Next Header field. The reassembled packet is then rejected because its
IPv6 version field has been corrupted.

Use int for prev_nhoff, matching the type of start and the prevhoff
output argument.

This was reproduced on Linux v7.2.8 with KASAN enabled. Before the
change, a control packet with the preceding Next Header field at offset
248 was delivered, while the equivalent packet at offset 256 was
dropped and Ip6InHdrErrors increased by one. After the change, both
packets were delivered and Ip6InHdrErrors did not increase. The
before/after result was reproduced twice.

Fixes: 9fb9cbb1082d ("[NETFILTER]: Add nf_conntrack subsystem.")
Cc: stable@vger.kernel.org
Signed-off-by: 성병찬 <tjdqudcks0424@naver.com>
---
 net/ipv6/netfilter/nf_conntrack_reasm.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/ipv6/netfilter/nf_conntrack_reasm.c b/net/ipv6/netfilter/nf_conntrack_reasm.c
index 599c49bf0a0a..be72c4346f8b 100644
--- a/net/ipv6/netfilter/nf_conntrack_reasm.c
+++ b/net/ipv6/netfilter/nf_conntrack_reasm.c
@@ -398,7 +398,7 @@ find_prev_fhdr(struct sk_buff *skb, u8 *prevhdrp, int *prevhoff, int *fhoff)
 {
 	u8 nexthdr = ipv6_hdr(skb)->nexthdr;
 	const int netoff = skb_network_offset(skb);
-	u8 prev_nhoff = netoff + offsetof(struct ipv6hdr, nexthdr);
+	int prev_nhoff = netoff + offsetof(struct ipv6hdr, nexthdr);
 	int start = netoff + sizeof(struct ipv6hdr);
 	int len = skb->len - start;
 	u8 prevhdr = NEXTHDR_IPV6;

base-commit: 72d3fcf802c45d00b300f25b848a93c3a2bd7c7e
-- 
2.43.0


^ permalink raw reply related	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-10-08  5:02 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-29  9:00 [PATCH net] netfilter: nf_conntrack_reasm: avoid truncating header offset tjdqudcks0424
2026-09-29  9:14 ` netdev-bot+sinfo
2026-10-02  0:02 ` netdev-bot+sashiko
2026-10-02  7:42   ` tjdqudcks0424
2026-10-07 22:57     ` Pablo Neira Ayuso
2026-10-08  5:02 ` [PATCH net v2] netfilter: nf_conntrack_reasm: avoid truncating header offsets sung byeongchan

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox