Linux Netfilter development
 help / color / mirror / Atom feed
* [BUG] netfilter: IPv6 conntrack fragment reassembly truncates header offset
@ 2026-09-29  5:34 성병찬
  2026-09-29  7:20 ` Florian Westphal
  0 siblings, 1 reply; 5+ messages in thread
From: 성병찬 @ 2026-09-29  5:34 UTC (permalink / raw)
  To: netfilter-devel; +Cc: pablo, fw, phil

Hello,

Resending in plain text because the mailing list rejected my previous
message.

I found a reproducible IPv6 conntrack fragment reassembly bug in:

  net/ipv6/netfilter/nf_conntrack_reasm.c

Tested kernel:

  Linux v7.2.8
  commit 9a66fdc0d7fd55f54235524a73435af99051e46f
  x86_64 with KASAN enabled

In find_prev_fhdr(), the previous Next Header offset is stored in u8:

  u8 prev_nhoff = netoff + offsetof(struct ipv6hdr, nexthdr);

A valid IPv6 extension-header chain can place this field at offset 256.
The value is then truncated to 0. During fragment reassembly,
nf_ct_frag6_reasm() modifies IPv6 header byte 0 instead of the Next
Header field at offset 256.

Results with the unmodified kernel, reproduced twice:

  control offset 248: delivered
  boundary offset 256: dropped
  Ip6InHdrErrors: increased by 1

I changed prev_nhoff from u8 to int and repeated the test twice:

  control offset 248: delivered
  boundary offset 256: delivered
  Ip6InHdrErrors: unchanged

No KASAN report, memory corruption, information disclosure, privilege
escalation, or firewall bypass was observed. I am reporting this as a
packet corruption/drop correctness bug.

The same u8 declaration appears to remain in current mainline.

I have a minimal C reproducer, configuration, logs, and before/after
results available.

Regards,
sungbyeongchan

^ permalink raw reply	[flat|nested] 5+ messages in thread
[parent not found: <31da96413a406da2116f44df2db84f@cweb009.nm>]

end of thread, other threads:[~2026-09-29  9:34 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-29  5:34 [BUG] netfilter: IPv6 conntrack fragment reassembly truncates header offset 성병찬
2026-09-29  7:20 ` Florian Westphal
2026-09-29  9:07   ` Pablo Neira Ayuso
     [not found] <31da96413a406da2116f44df2db84f@cweb009.nm>
2026-09-29  9:01 ` Pablo Neira Ayuso
2026-09-29  9:14   ` 성병찬

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox