From: Jerome Forissier <jerome.forissier@arm.com>
To: "estebancalba@gmail.com" <estebancalba@gmail.com>,
"u-boot@lists.u-boot-project.org"
<u-boot@lists.u-boot-project.org>
Cc: "trini@konsulko.com" <trini@konsulko.com>,
"rfried.dev@gmail.com" <rfried.dev@gmail.com>,
"v.v.mitrofanov@yadro.com" <v.v.mitrofanov@yadro.com>,
"sjg@chromium.org" <sjg@chromium.org>, nd <nd@arm.com>
Subject: Re: [PATCH v2] net: net6: validate IPv6 payload and transport lengths on receive
Date: Thu, 3 Sep 2026 11:23:42 +0200 [thread overview]
Message-ID: <45cf6b6b-231e-43be-a93d-3ac30510c01c@arm.com> (raw)
In-Reply-To: <20260821-net6-len-validation-v2-1-29bd39f946e0@gmail.com>
Hi Esteban,
On 21/08/2026 09:07, Esteban Alba via B4 Relay wrote:
> From: Esteban Alba <estebancalba@gmail.com>
>
> net_ip6_handler() checks the received length only against IP6_HDR_SIZE and
> then uses length fields from the packet without checking them. The checksum
> is computed over payload_len, but the UDP handler length comes from
> udp_len. A sender can keep payload_len correct so the checksum still
> validates and set udp_len larger than the frame. A handler that trusts that
> length then reads or writes past the receive buffer. The DHCPv6 client
> copies the declared number of bytes and can be made to write past the
> packet buffer from a single link-local ADVERTISE.
>
> Validate payload_len against the received length and trim len to it before
> protocol dispatch. Validate the ICMPv6 and UDP header sizes before either
> header is dereferenced, and validate udp_len before reading udp_xsum or
> calling the UDP handler.
>
> Fixes: 1feb697830ce ("net: ipv6: Add implementation of main IPv6 functions")
> Suggested-by: Jerome Forissier <jerome.forissier@arm.com>
> Signed-off-by: Esteban Alba <estebancalba@gmail.com>
> ---
> Validate the IPv6 payload length against the received frame before protocol
> dispatch, then validate the ICMPv6 and UDP transport header sizes and
> udp_len before either header is dereferenced or the UDP handler is called.
> ---
> Changes in v2:
> - Move payload_len reconciliation before protocol dispatch.
> - Validate ICMPv6 and UDP header sizes before dereferencing their headers.
> - Validate udp_len before reading udp_xsum or dispatching to the UDP handler.
> - Link to v1: https://patch.msgid.link/20260807-net6-len-validation-v1-1-edff271cbf2c@gmail.com
>
> To: u-boot@lists.u-boot-project.org
> Cc: Ramon Fried <rfried.dev@gmail.com>
> Cc: Jerome Forissier <jerome.forissier@arm.com>
> Cc: Tom Rini <trini@konsulko.com>
> Cc: Viacheslav Mitrofanov <v.v.mitrofanov@yadro.com>
> Cc: Simon Glass <sjg@chromium.org>
> ---
> net/net6.c | 18 ++++++++++++++++--
> 1 file changed, 16 insertions(+), 2 deletions(-)
>
> diff --git a/net/net6.c b/net/net6.c
> index 4cff98df15..e1a455748e 100644
> --- a/net/net6.c
> +++ b/net/net6.c
> @@ -392,11 +392,19 @@ int net_ip6_handler(struct ethernet_hdr *et, struct ip6_hdr *ip6, int len)
> if (ip6->version != 6)
> return -EINVAL;
>
> + hlen = ntohs(ip6->payload_len);
> +
> + if (len < IP6_HDR_SIZE + hlen)
> + return -EINVAL;
> + len = IP6_HDR_SIZE + hlen;
> +
> switch (ip6->nexthdr) {
> case PROT_ICMPV6:
> + if (hlen < sizeof(struct icmp6hdr))
> + return -EINVAL;
> +
> icmp = (struct icmp6hdr *)(((uchar *)ip6) + IP6_HDR_SIZE);
> csum = icmp->icmp6_cksum;
> - hlen = ntohs(ip6->payload_len);
> icmp->icmp6_cksum = 0;
> /* checksum */
> csum_p = csum_partial((u8 *)icmp, hlen, 0);
> @@ -421,9 +429,15 @@ int net_ip6_handler(struct ethernet_hdr *et, struct ip6_hdr *ip6, int len)
> }
> break;
> case IPPROTO_UDP:
> + if (hlen < UDP_HDR_SIZE)
> + return -EINVAL;
> +
> udp = (struct udp_hdr *)(((uchar *)ip6) + IP6_HDR_SIZE);
> + if (ntohs(udp->udp_len) < UDP_HDR_SIZE ||
> + ntohs(udp->udp_len) > hlen)
> + return -EINVAL;
> +
> csum = udp->udp_xsum;
> - hlen = ntohs(ip6->payload_len);
> udp->udp_xsum = 0;
> /* checksum */
> csum_p = csum_partial((u8 *)udp, hlen, 0);
>
> ---
> base-commit: ece349ade2973e220f524ce59e59711cc919263f
> change-id: 20260807-net6-len-validation-cd71efd96a7f
>
> Best regards,
> --
> Esteban Alba <estebancalba@gmail.com>
Reviewed-by: Jerome Forissier <jerome.forissier@arm.com>
Thanks,
--
Jerome
next prev parent reply other threads:[~2026-09-03 9:24 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-08 2:09 [PATCH] net: net6: validate IPv6 payload and UDP length on receive Esteban Alba via B4 Relay
2026-08-14 8:05 ` Jerome Forissier
2026-08-21 7:07 ` [PATCH v2] net: net6: validate IPv6 payload and transport lengths " Esteban Alba via B4 Relay
2026-09-03 9:23 ` Jerome Forissier [this message]
2026-09-11 13:18 ` Jerome Forissier
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=45cf6b6b-231e-43be-a93d-3ac30510c01c@arm.com \
--to=jerome.forissier@arm.com \
--cc=estebancalba@gmail.com \
--cc=nd@arm.com \
--cc=rfried.dev@gmail.com \
--cc=sjg@chromium.org \
--cc=trini@konsulko.com \
--cc=u-boot@lists.u-boot-project.org \
--cc=v.v.mitrofanov@yadro.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox