U-Boot Archive on lore.kernel.org
 help / color / mirror / Atom feed
From: Jerome Forissier <jerome.forissier@arm.com>
To: "estebancalba@gmail.com" <estebancalba@gmail.com>,
	"u-boot@lists.u-boot-project.org"
	<u-boot@lists.u-boot-project.org>
Cc: "trini@konsulko.com" <trini@konsulko.com>,
	"rfried.dev@gmail.com" <rfried.dev@gmail.com>,
	"v.v.mitrofanov@yadro.com" <v.v.mitrofanov@yadro.com>,
	"sjg@chromium.org" <sjg@chromium.org>, nd <nd@arm.com>
Subject: Re: [PATCH v2] net: net6: validate IPv6 payload and transport lengths on receive
Date: Thu, 3 Sep 2026 11:23:42 +0200	[thread overview]
Message-ID: <45cf6b6b-231e-43be-a93d-3ac30510c01c@arm.com> (raw)
In-Reply-To: <20260821-net6-len-validation-v2-1-29bd39f946e0@gmail.com>

Hi Esteban,

On 21/08/2026 09:07, Esteban Alba via B4 Relay wrote:
> From: Esteban Alba <estebancalba@gmail.com>
> 
> net_ip6_handler() checks the received length only against IP6_HDR_SIZE and
> then uses length fields from the packet without checking them. The checksum
> is computed over payload_len, but the UDP handler length comes from
> udp_len. A sender can keep payload_len correct so the checksum still
> validates and set udp_len larger than the frame. A handler that trusts that
> length then reads or writes past the receive buffer. The DHCPv6 client
> copies the declared number of bytes and can be made to write past the
> packet buffer from a single link-local ADVERTISE.
> 
> Validate payload_len against the received length and trim len to it before
> protocol dispatch. Validate the ICMPv6 and UDP header sizes before either
> header is dereferenced, and validate udp_len before reading udp_xsum or
> calling the UDP handler.
> 
> Fixes: 1feb697830ce ("net: ipv6: Add implementation of main IPv6 functions")
> Suggested-by: Jerome Forissier <jerome.forissier@arm.com>
> Signed-off-by: Esteban Alba <estebancalba@gmail.com>
> ---
> Validate the IPv6 payload length against the received frame before protocol
> dispatch, then validate the ICMPv6 and UDP transport header sizes and
> udp_len before either header is dereferenced or the UDP handler is called.
> ---
> Changes in v2:
> - Move payload_len reconciliation before protocol dispatch.
> - Validate ICMPv6 and UDP header sizes before dereferencing their headers.
> - Validate udp_len before reading udp_xsum or dispatching to the UDP handler.
> - Link to v1: https://patch.msgid.link/20260807-net6-len-validation-v1-1-edff271cbf2c@gmail.com
> 
> To: u-boot@lists.u-boot-project.org
> Cc: Ramon Fried <rfried.dev@gmail.com>
> Cc: Jerome Forissier <jerome.forissier@arm.com>
> Cc: Tom Rini <trini@konsulko.com>
> Cc: Viacheslav Mitrofanov <v.v.mitrofanov@yadro.com>
> Cc: Simon Glass <sjg@chromium.org>
> ---
>  net/net6.c | 18 ++++++++++++++++--
>  1 file changed, 16 insertions(+), 2 deletions(-)
> 
> diff --git a/net/net6.c b/net/net6.c
> index 4cff98df15..e1a455748e 100644
> --- a/net/net6.c
> +++ b/net/net6.c
> @@ -392,11 +392,19 @@ int net_ip6_handler(struct ethernet_hdr *et, struct ip6_hdr *ip6, int len)
>  	if (ip6->version != 6)
>  		return -EINVAL;
>  
> +	hlen = ntohs(ip6->payload_len);
> +
> +	if (len < IP6_HDR_SIZE + hlen)
> +		return -EINVAL;
> +	len = IP6_HDR_SIZE + hlen;
> +
>  	switch (ip6->nexthdr) {
>  	case PROT_ICMPV6:
> +		if (hlen < sizeof(struct icmp6hdr))
> +			return -EINVAL;
> +
>  		icmp = (struct icmp6hdr *)(((uchar *)ip6) + IP6_HDR_SIZE);
>  		csum = icmp->icmp6_cksum;
> -		hlen = ntohs(ip6->payload_len);
>  		icmp->icmp6_cksum = 0;
>  		/* checksum */
>  		csum_p = csum_partial((u8 *)icmp, hlen, 0);
> @@ -421,9 +429,15 @@ int net_ip6_handler(struct ethernet_hdr *et, struct ip6_hdr *ip6, int len)
>  		}
>  		break;
>  	case IPPROTO_UDP:
> +		if (hlen < UDP_HDR_SIZE)
> +			return -EINVAL;
> +
>  		udp = (struct udp_hdr *)(((uchar *)ip6) + IP6_HDR_SIZE);
> +		if (ntohs(udp->udp_len) < UDP_HDR_SIZE ||
> +		    ntohs(udp->udp_len) > hlen)
> +			return -EINVAL;
> +
>  		csum = udp->udp_xsum;
> -		hlen = ntohs(ip6->payload_len);
>  		udp->udp_xsum = 0;
>  		/* checksum */
>  		csum_p = csum_partial((u8 *)udp, hlen, 0);
> 
> ---
> base-commit: ece349ade2973e220f524ce59e59711cc919263f
> change-id: 20260807-net6-len-validation-cd71efd96a7f
> 
> Best regards,
> --  
> Esteban Alba <estebancalba@gmail.com>

Reviewed-by: Jerome Forissier <jerome.forissier@arm.com>

Thanks,
-- 
Jerome

  reply	other threads:[~2026-09-03  9:24 UTC|newest]

Thread overview: 5+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-08-08  2:09 [PATCH] net: net6: validate IPv6 payload and UDP length on receive Esteban Alba via B4 Relay
2026-08-14  8:05 ` Jerome Forissier
2026-08-21  7:07 ` [PATCH v2] net: net6: validate IPv6 payload and transport lengths " Esteban Alba via B4 Relay
2026-09-03  9:23   ` Jerome Forissier [this message]
2026-09-11 13:18   ` Jerome Forissier

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=45cf6b6b-231e-43be-a93d-3ac30510c01c@arm.com \
    --to=jerome.forissier@arm.com \
    --cc=estebancalba@gmail.com \
    --cc=nd@arm.com \
    --cc=rfried.dev@gmail.com \
    --cc=sjg@chromium.org \
    --cc=trini@konsulko.com \
    --cc=u-boot@lists.u-boot-project.org \
    --cc=v.v.mitrofanov@yadro.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox