From: Guo Zihao <guozh23@xiaopeng.com>
To: netdev-bot+sinfo@kernel.org
Cc: Pablo Neira Ayuso <pablo@netfilter.org>,
Florian Westphal <fw@strlen.de>, Phil Sutter <phil@nwl.cc>,
Nikolay Aleksandrov <razor@blackwall.org>,
Ido Schimmel <idosch@nvidia.com>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
Simon Horman <horms@kernel.org>,
netfilter-devel@vger.kernel.org, coreteam@netfilter.org,
bridge@lists.linux.dev, netdev@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH] netfilter: ebtables: ebt_802_3: drop short frames before the match reads LLC
Date: Mon, 28 Sep 2026 16:41:43 +0800 [thread overview]
Message-ID: <20260928084143.3163008-1-guozh23@xiaopeng.com> (raw)
In-Reply-To: <20260928082858.3009191-1-guozh23@xiaopeng.com>
Hi,
Replying to the bot's two questions:
1. How the issue was discovered
Manual code inspection, combined with a static-analysis scan of net/
that flagged the unchecked skb_mac_header() dereference in
ebt_802_3_mt(). After the scan report I read the surrounding code by
hand (ebtables.c ebt_do_table()/ebt_basic_match(), the bridge RX path,
and eth_type_trans()) to confirm that nothing between the RX entry and
this match guarantees more than ETH_HLEN (14) linear bytes past the mac
header is available, and that no pskb_may_pull() runs in between.
2. Whether the issue was actually triggered
Not triggered. This is theoretical, found by code inspection only.
There is no runtime report, stack trace, or crash log on my side. The
reasoning chain is:
- ebt_802_3_mt() casts skb_mac_header(skb) directly to
struct ebt_802_3_hdr * and dereferences fields up to machdr + 22
(the ni branch of the LLC union).
- The ebtables core never calls pskb_may_pull() before running the
per-rule matches.
- So an 802.3 frame (length field below 1536) whose skb carries
nothing past the 14-byte Ethernet header reaches the match with
machdr + 22 pointing into tailroom.
The fix in the patch deliberately chooses a conservative predicate:
it drops the packet whenever fewer than (ETH_HLEN + ebt 802.3 header
size) bytes are linear, which can also drop frames whose LLC union is
technically still inside the linear area but shorter than that. In
practice the minimum Ethernet frame is 60 bytes, so skb_headlen under
37 only occurs on truncated or malformed frames, where dropping is
the reasonable response. Fixing a potential OOB read is not worth
adding a second rule for.
If a runtime reproducer is needed, I can build one with a raw socket
and a veth pair, but I think the code-level analysis is conclusive.
Guo Zihao
next prev parent reply other threads:[~2026-09-28 8:41 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-28 8:28 [PATCH] netfilter: ebtables: ebt_802_3: drop short frames before the match reads LLC Guo Zihao
2026-09-28 8:35 ` netdev-bot+sinfo
2026-09-28 8:41 ` Guo Zihao [this message]
2026-09-30 14:30 ` netdev-bot+sashiko
2026-10-08 2:45 ` Guo Zihao
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260928084143.3163008-1-guozh23@xiaopeng.com \
--to=guozh23@xiaopeng.com \
--cc=bridge@lists.linux.dev \
--cc=coreteam@netfilter.org \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=fw@strlen.de \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev-bot+sinfo@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=pablo@netfilter.org \
--cc=phil@nwl.cc \
--cc=razor@blackwall.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox