From: Nicolas Dichtel <nicolas.dichtel@6wind.com>
To: David Lee <david.lee@trailofbits.com>
Cc: andrea.mayer@uniroma2.it, davem@davemloft.net,
edumazet@google.com, kuba@kernel.org, pabeni@redhat.com,
Kyle Zeng <kylebot@openai.com>,
Dominik 'Disconnect3d' Czarnota
<dominik.czarnota@trailofbits.com>,
horms@kernel.org, netdev@vger.kernel.org,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH net v2] ipv6: seg6: clear IPv4 control block in End.DT4
Date: Wed, 5 Aug 2026 13:58:21 +0200 [thread overview]
Message-ID: <e7eb5ac7-7b5d-4484-aa66-4c92bb20c538@6wind.com> (raw)
In-Reply-To: <CAC_etQFJTsCN5zr_gxO_SEDjbJU4-yph0ezbvQ6zZ9ZVaLie0w@mail.gmail.com>
Le 05/08/2026 à 12:17, David Lee a écrit :
> Hi Nicoals,
Hi,
please avoid top-posting ;-)
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/tree/Documentation/process/submitting-patches.rst#n336
>
> You were right. I tested End.DX4 separately on the 62cc90241548 (v7.2-rc5)
> kernel and it produced:
>
> BUG: KASAN: slab-out-of-bounds in __ip_options_echo()
> Write of size 255
>
> The stack contains both input_action_end_dx4_finish() and
> input_action_end_dx4(). A matched bounded control traversed End.DX4,
> reached SYN_RECV, and produced no kernel diagnostic.
>
> Therefore, End.DX4 has the same stale IP6CB-to-IPCB issue. The current
> patch only clears IPCB in End.DT4 and is incomplete.
>
> Do you prefer v3 to be sent out to cover this case too?
Yes, it would be nice to fix both in the same time.
Regards,
Nicolas
prev parent reply other threads:[~2026-08-05 11:58 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-04 9:46 [PATCH net v2] ipv6: seg6: clear IPv4 control block in End.DT4 David Lee
2026-08-04 14:50 ` Nicolas Dichtel
[not found] ` <CAC_etQFJTsCN5zr_gxO_SEDjbJU4-yph0ezbvQ6zZ9ZVaLie0w@mail.gmail.com>
2026-08-05 11:58 ` Nicolas Dichtel [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e7eb5ac7-7b5d-4484-aa66-4c92bb20c538@6wind.com \
--to=nicolas.dichtel@6wind.com \
--cc=andrea.mayer@uniroma2.it \
--cc=davem@davemloft.net \
--cc=david.lee@trailofbits.com \
--cc=dominik.czarnota@trailofbits.com \
--cc=edumazet@google.com \
--cc=horms@kernel.org \
--cc=kuba@kernel.org \
--cc=kylebot@openai.com \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox