Netdev List
 help / color / mirror / Atom feed
From: Ren Wei <weir@nebusec.ai>
To: netdev@vger.kernel.org, intel-wired-lan@lists.osuosl.org
Cc: dsahern@kernel.org, idosch@nvidia.com, davem@davemloft.net,
	edumazet@kernel.org, kuba@kernel.org, pabeni@redhat.com,
	horms@kernel.org, steffen.klassert@secunet.com,
	herbert@gondor.apana.org.au, lucien.xin@gmail.com,
	anthony.l.nguyen@intel.com, przemyslaw.kitszel@intel.com,
	jbrandeb@kernel.org, sln@onemain.com, fw@strlen.de,
	petalzu987@gmail.com, weir@nebusec.ai
Subject: [PATCH net v1 1/2] ipv6: reject truncated extension headers in ipv6_skip_exthdr()
Date: Sun, 27 Sep 2026 02:23:08 +0800	[thread overview]
Message-ID: <f9abb4c3ba2b50f982ddca240012f8a782c9958e.1790082243.git.petalzu987@gmail.com> (raw)
In-Reply-To: <cover.1790082243.git.petalzu987@gmail.com>

From: Zixuan Chai <petalzu987@gmail.com>

ipv6_skip_exthdr() derives the length of each extension header from packet
data. When the packet ends before the declared length, it currently
advances the offset past the end of the skb and reports a successful
parse.

Check the remaining skb length before advancing over an extension header.
Handle the resulting -1 in the consumers that use the offset or classify
the first fragment: reject malformed first fragments during IPv6
reassembly, including conntrack reassembly; suppress ICMPv6 replies; and
abort XFRM BEET GSO before updating the transport offset.

Update the helper comment to describe the -1 failure result.

Fixes: 25a44ae93d1a ("esp6: support ipv6 nexthdrs process for beet gso segment")
Fixes: 6f297068a069 ("esp4: support ipv6 nexthdrs process for beet gso segment")
Cc: stable@vger.kernel.org
Reported-by: Florian Westphal <fw@strlen.de>
Closes: https://lore.kernel.org/netfilter-devel/aq1HaYS96SNn7HJY@strlen.de/
Assisted-by: LLM
Signed-off-by: Zixuan Chai <petalzu987@gmail.com>
Signed-off-by: Ren Wei <weir@nebusec.ai>
---
 include/net/ipv6_frag.h |  4 +++-
 net/ipv4/esp4_offload.c |  8 ++++++--
 net/ipv6/esp6_offload.c |  8 ++++++--
 net/ipv6/exthdrs_core.c | 14 +++++++-------
 net/ipv6/icmp.c         |  2 +-
 5 files changed, 23 insertions(+), 13 deletions(-)

diff --git a/include/net/ipv6_frag.h b/include/net/ipv6_frag.h
index 41d9fc6965f9..5616f6e7428d 100644
--- a/include/net/ipv6_frag.h
+++ b/include/net/ipv6_frag.h
@@ -125,7 +125,9 @@ ipv6frag_thdr_truncated(struct sk_buff *skb, int start, u8 *nexthdrp)
 	int offset;
 
 	offset = ipv6_skip_exthdr(skb, start, &nexthdr, &frag_off);
-	if (offset < 0 || (frag_off & htons(IP6_OFFSET)))
+	if (offset < 0)
+		return true;
+	if (frag_off & htons(IP6_OFFSET))
 		return false;
 	switch (nexthdr) {
 	case NEXTHDR_TCP:
diff --git a/net/ipv4/esp4_offload.c b/net/ipv4/esp4_offload.c
index abd77162f5e7..a29e79a8b924 100644
--- a/net/ipv4/esp4_offload.c
+++ b/net/ipv4/esp4_offload.c
@@ -168,10 +168,14 @@ static struct sk_buff *xfrm4_beet_gso_segment(struct xfrm_state *x,
 			skb->transport_header -= IPV4_BEET_PHMAXLEN;
 		}
 	} else {
 		__be16 frag;
+		int offset;
 
-		skb->transport_header +=
-			ipv6_skip_exthdr(skb, 0, &proto, &frag);
+		offset = ipv6_skip_exthdr(skb, 0, &proto, &frag);
+		if (offset < 0)
+			return ERR_PTR(-EINVAL);
+
+		skb->transport_header += offset;
 		if (proto == IPPROTO_TCP)
 			skb_shinfo(skb)->gso_type |= SKB_GSO_TCPV4;
 	}
diff --git a/net/ipv6/esp6_offload.c b/net/ipv6/esp6_offload.c
index 22895521a57d..2fbf6f567a50 100644
--- a/net/ipv6/esp6_offload.c
+++ b/net/ipv6/esp6_offload.c
@@ -210,10 +210,14 @@ static struct sk_buff *xfrm6_beet_gso_segment(struct xfrm_state *x,
 		if (proto == IPPROTO_TCP)
 			skb_shinfo(skb)->gso_type |= SKB_GSO_TCPV6;
 	} else {
 		__be16 frag;
+		int offset;
 
-		skb->transport_header +=
-			ipv6_skip_exthdr(skb, 0, &proto, &frag);
+		offset = ipv6_skip_exthdr(skb, 0, &proto, &frag);
+		if (offset < 0)
+			return ERR_PTR(-EINVAL);
+
+		skb->transport_header += offset;
 	}
 
 	if (proto == IPPROTO_IPIP)
diff --git a/net/ipv6/exthdrs_core.c b/net/ipv6/exthdrs_core.c
index 4a9748338cf4..60e20036c1bd 100644
--- a/net/ipv6/exthdrs_core.c
+++ b/net/ipv6/exthdrs_core.c
@@ -48,15 +48,12 @@ EXPORT_SYMBOL(ipv6_ext_hdr);
  * "nexthdrp" initially points to some place,
  * where type of the first header can be found.
  *
- * It skips all well-known exthdrs, and returns pointer to the start
- * of unparsable area i.e. the first header with unknown type.
+ * It skips all well-known exthdrs, and returns the offset of the start
+ * of the first header with an unknown type.
  * If it is not NULL *nexthdr is updated by type/protocol of this header.
  *
- * NOTES: - if packet terminated with NEXTHDR_NONE it returns NULL.
- *        - it may return pointer pointing beyond end of packet,
- *	    if the last recognized header is truncated in the middle.
- *        - if packet is truncated, so that all parsed headers are skipped,
- *	    it returns NULL.
+ * NOTES: - if packet terminates with NEXTHDR_NONE or is truncated while
+ *          skipping extension headers, it returns -1.
  *	  - First fragment header is skipped, not-first ones
  *	    are considered as unparsable.
  *	  - Reports the offset field of the final fragment header so it is
@@ -107,6 +104,9 @@ int ipv6_skip_exthdr(const struct sk_buff *skb, int start, u8 *nexthdrp,
 		else
 			hdrlen = ipv6_optlen(hp);
 
+		if (skb->len - start < hdrlen)
+			return -1;
+
 		nexthdr = hp->nexthdr;
 		start += hdrlen;
 	}
diff --git a/net/ipv6/icmp.c b/net/ipv6/icmp.c
index a95b0351824f..8896ac90343e 100644
--- a/net/ipv6/icmp.c
+++ b/net/ipv6/icmp.c
@@ -145,7 +145,7 @@ static bool is_ineligible(const struct sk_buff *skb)
 
 	ptr = ipv6_skip_exthdr(skb, ptr, &nexthdr, &frag_off);
 	if (ptr < 0)
-		return false;
+		return true;
 	if (nexthdr == IPPROTO_ICMPV6) {
 		u8 _type, *tp;
 		tp = skb_header_pointer(skb,
-- 
2.34.1

  reply	other threads:[~2026-09-26 18:23 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-26 18:23 [PATCH net v1 0/2] net: validate malformed IPv6 and TCP headers Ren Wei
2026-09-26 18:23 ` Ren Wei [this message]
2026-09-26 18:23 ` [PATCH net v1 2/2] i40e: validate TCP header before ATR access Ren Wei
2026-09-27 13:59   ` Eric Dumazet
2026-09-29  6:30   ` Loktionov, Aleksandr

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=f9abb4c3ba2b50f982ddca240012f8a782c9958e.1790082243.git.petalzu987@gmail.com \
    --to=weir@nebusec.ai \
    --cc=anthony.l.nguyen@intel.com \
    --cc=davem@davemloft.net \
    --cc=dsahern@kernel.org \
    --cc=edumazet@kernel.org \
    --cc=fw@strlen.de \
    --cc=herbert@gondor.apana.org.au \
    --cc=horms@kernel.org \
    --cc=idosch@nvidia.com \
    --cc=intel-wired-lan@lists.osuosl.org \
    --cc=jbrandeb@kernel.org \
    --cc=kuba@kernel.org \
    --cc=lucien.xin@gmail.com \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=petalzu987@gmail.com \
    --cc=przemyslaw.kitszel@intel.com \
    --cc=sln@onemain.com \
    --cc=steffen.klassert@secunet.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox