netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [PATCH net] ipv6: un-do: defrag: drop non-last frags smaller than min mtu
@ 2019-04-05  0:18 Captain Wiggum
  2019-04-05  4:50 ` Greg Kroah-Hartman
  0 siblings, 1 reply; 14+ messages in thread
From: Captain Wiggum @ 2019-04-05  0:18 UTC (permalink / raw)
  To: Greg Kroah-Hartman
  Cc: Florian Westphal, Eric Dumazet, Peter Oskolkov, netdev, stable

Hi Greg,

A previous bad patch breaks 18 test cases for IPv6 fragment headers.
This has already been un-done in upstream, but not in any of the LTS.
However two upstream patches are first needed to cover a DoS vulnerability.

For background, there are two mail threads in [netdev] on this subject:
1) Subject: TAHI testing fails for IPv6 Fragments in Kernel 4.9 (from
captwiggum)
2) Subject: Please merge IPv6 fix for drop fragment smaller than MTU
(from captwiggum)

Two patches from upstream needed first to cover the DoS:

commit d4289fcc9b16b89619ee1c54f829e05e56de8b9a
net: IP6 defrag: use rbtrees for IPv6 defrag

commit 997dd96471641e147cb2c33ad54284000d0f5e35
net: IP6 defrag: use rbtrees in nf_conntrack_reasm.c

One undo-patch to fix the IPv6 fragment headers:

ipv6: defrag: drop non-last frags smaller than min mtu
UN-DO: commit a8444b1ccb20339774af58e40ad42296074fb484

Thanks!

--John Masinter (captwiggum)

^ permalink raw reply	[flat|nested] 14+ messages in thread

end of thread, other threads:[~2019-04-08 23:39 UTC | newest]

Thread overview: 14+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2019-04-05  0:18 [PATCH net] ipv6: un-do: defrag: drop non-last frags smaller than min mtu Captain Wiggum
2019-04-05  4:50 ` Greg Kroah-Hartman
2019-04-05 16:22   ` Captain Wiggum
2019-04-06 14:15     ` Sasha Levin
2019-04-06 16:34       ` Florian Westphal
2019-04-08 14:49       ` Captain Wiggum
2019-04-08 14:54         ` Eric Dumazet
2019-04-08 15:09           ` Captain Wiggum
2019-04-08 15:51         ` Sasha Levin
2019-04-08 15:59           ` Peter Oskolkov
2019-04-08 16:29             ` Captain Wiggum
2019-04-08 17:13               ` Peter Oskolkov
2019-04-08 23:15                 ` Sasha Levin
2019-04-08 23:38                   ` Peter Oskolkov

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).