From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f43.google.com (mail-qv1-f43.google.com [209.85.219.43]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 1019F31AABF for ; Tue, 4 Aug 2026 06:10:57 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.43 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785823859; cv=none; b=SNgggGkDVb7EP1W2/eZ1XCuqeDvdKyVO63/icVRCHm8i1pDB/t1Tf9ljNDbHSCQgwO6vsKJAWFKpkNtvycjis4aOFfjTVKa9dSXczu36aweN+fvb1wjd6Rpdfq6/xzqZj1TCyeL7VZw2BEKJ8YrLi8iDHvWe/95Qj1FjxZGpx2o= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785823859; c=relaxed/simple; bh=6L1PVLST7v1nkRF+r8Iv2XGopCR5emnQnssaQ73pjKE=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=iosKEQ0LIsWUZk5etChFINPALQvRoTs5HX+WArkL7DM7TQpFTOLqDoCis1WtHol/W+I9rS+KMpSq1B8GH4DMHRUhSuBP6EtTcXJvJPsNmw+TTdPdHu+34bAu2IpN95/mW+Uzz0p0YW7G7heYAqK4sCjuoooybVUpzOGAme2GxDU= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=VLfa1xOg; arc=none smtp.client-ip=209.85.219.43 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="VLfa1xOg" Received: by mail-qv1-f43.google.com with SMTP id 6a1803df08f44-8eeb4508f29so28995306d6.0 for ; Mon, 03 Aug 2026 23:10:57 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1785823857; x=1786428657; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to:content-type; bh=DuDYSjJQEMSMyuu+bbvopLn43BBsmPMFs7o1wHmptzs=; b=VLfa1xOgk01S0I2L6YD4aRtKIaQinZJQojLMS+83TLQgeFf4npsXh9E93ApIT1LL5/ hawKrs8rZBJJwKbQsQR8Nnha6DM89JW1ZWX/Uoq0jRO2sVwiT/Pog1WwGuYlV19Sttzp XR64xo1TYSz8hSq969/dRX7Z/nrxePk3psYqiIo9eqPvhE7edxq/tVWtKCq6BoRbYVOV tvuf+H2uTkJDsf8612X+N6vE9erSzQZ89iWpSelr1UqSlXjiKwNPCVTT2E0bw7YQT/Or RBBQwHsAnwF/kMUCpfzfj4zG5aTj8scSOR3dEGkbmr3qIpuoAkGIQxDhhVqusX8BC10J 0EQQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785823857; x=1786428657; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to:content-type; bh=DuDYSjJQEMSMyuu+bbvopLn43BBsmPMFs7o1wHmptzs=; b=gPBKvmRzJjzv2r0YplOyqEPNU1snm4yt+HHCIxPY7CLl5ZKcvwqhRvAlVDcAhDyDKi hNFJuyaxVp+d1kLGPn3aOzKHU+fI7nfSGdhjDCqBTRSLEiBa+cVvl/M8kwHTuNcbCcHo TElHQTAAX/lzAVqfsLtWAEKBH9Z/AbGBuE3MHsNmcrnc38XbkpIzO75COzCUlvzci8Bq 2exhWQNyOXaiQBUxZc0DM+Qp5yuGExnrnplkKLQdxIpKP5CktyGYjLrTnkRVCjNN+gQt MDBgJtnVChQYuNA/WAgQVE1Lp1m2VTEV24VdgLQlbDv4TWq43kaQpfwO0elP8c59NeTy gsVQ== X-Forwarded-Encrypted: i=1; AHgh+RqLMEz4aEiIVrb/FeGClX4rWYEZ3FTTjK48lulwyXUEHQ1u2IC32hXV5fcfwlhK53Ap2kL5edabyTQYds8=@vger.kernel.org X-Gm-Message-State: AOJu0YwMNyy01mQgIPA2fa0m3e7jM/M7g0+Zi77dqvxRqp9E4G4b28ZW NyBatekIE7iKuw5KTO3kzRX6XLvBF2PzT7dG2mp1qhci4jKbUYcev6s2aO24lrZKj7o= X-Gm-Gg: AR+sD10R8lOglC6JZ0WpzsEKy72tfECiOEWtk7wT4e10LtwmM/m3SKPLPDYDyCXRliK x/qJFZAf+hbylGqcJxGWimmCogWwi8pDyO+aoEL4GCyD9pZj0bPPit06gCTbyAqOG54msLlfQQa 77GXL7Ne8YC09N89cXwC87fgHCnTxESIv1uIMbODa/Pn6w65PT4nL3mUUnp/Hc2ZzhNwq68Vvvw Dh28vC4+uC/fKncboy+1uN2tCm0HhOxwvK4aVCqOHkAnKvI0xc2iwB42eB7zLmsgvC6gQjzpRp4 cCupljaTOHtmKE3EaD2+eRMXp62B47S7WrfWJvAXyikYkanybMX2FvtIQN0o4Oo4Huon/NEcxze 36tBAs7kR7Vfi/wJaVE+FotavF8fq9imVsKQ2XU0TdyN9ToMVJxNd6hdJ7/lRBjpHQgKTfFZ0JD Howwzr6GwuXWI0ok//gmQbuOjphTgEoWV/ZH7YvDYzBLQ6IbrNED0Qj06Q9TpMCtUeug== X-Received: by 2002:a05:6214:2f02:b0:8ea:184f:c15a with SMTP id 6a1803df08f44-90849600a6emr294349336d6.17.1785823856908; Mon, 03 Aug 2026 23:10:56 -0700 (PDT) Received: from localhost ([146.190.222.192]) by smtp.gmail.com with UTF8SMTPSA id 6a1803df08f44-908435eab41sm92617856d6.34.2026.08.03.23.10.56 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 03 Aug 2026 23:10:56 -0700 (PDT) From: David Lee To: horms@verge.net.au, ja@ssi.bg, pablo@netfilter.org, fw@strlen.de, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com Cc: Kyle Zeng , Dominik 'Disconnect3d' Czarnota , Sven Eckelmann , phil@nwl.cc, netdev@vger.kernel.org, lvs-devel@vger.kernel.org, netfilter-devel@vger.kernel.org, coreteam@netfilter.org, linux-kernel@vger.kernel.org, stable@vger.kernel.org, David Lee Subject: [PATCH nf v2] ipvs: clear IPv4 options after rebasing tunnel ICMP errors Date: Tue, 4 Aug 2026 06:10:55 +0000 Message-ID: <20260804061055.711402-1-david.lee@trailofbits.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit From: Kyle Zeng ip_vs_in_icmp() rebases an skb from the outer ICMP packet to the quoted original request before passing it to icmp_send(). However, IPCB(skb)->opt still describes the outer IPv4 header. A timestamp option in the outer header can therefore leave an offset that points into the quoted transport header after the rebase. __ip_options_echo() treats a byte at that stale location as the option length and copies it into the fixed-size option storage on the __icmp_send() stack, causing a stack out-of-bounds write. Clear the stale option metadata after resetting the network header. Keep the remaining control block fields, including the ingress interface used by the ICMP response path. Fixes: f2edb9f7706d ("ipvs: implement passive PMTUD for IPIP packets") Cc: stable@vger.kernel.org Assisted-by: Codex:gpt-5.6-sol Codex:gpt-5.5-cyber Signed-off-by: Kyle Zeng Co-developed-by: David Lee Signed-off-by: David Lee --- Changes in v2: - Add the nf tree prefix to the subject. - Restore Kyle Zeng as the patch author and correct the sign-off chain. - Move the research credit below the commit-message separator. v1: https://lore.kernel.org/netdev/20260731140822.567128-1-david.lee@trailofbits.com/ Bug found and triaged by OpenAI Security Research and validated by Trail of Bits. Trail of Bits has a reproducer for this bug that triggers a KASAN stack-out-of-bounds write in __ip_options_echo() and can share if needed. net/netfilter/ipvs/ip_vs_core.c | 1 + 1 file changed, 1 insertion(+) diff --git a/net/netfilter/ipvs/ip_vs_core.c b/net/netfilter/ipvs/ip_vs_core.c index bafab9345..fe06c380c 100644 --- a/net/netfilter/ipvs/ip_vs_core.c +++ b/net/netfilter/ipvs/ip_vs_core.c @@ -1951,6 +1951,7 @@ ip_vs_in_icmp(struct netns_ipvs *ipvs, struct sk_buff *skb, int *related, if (pskb_pull(skb, offset2) == NULL) goto ignore_tunnel; skb_reset_network_header(skb); + memset(&(IPCB(skb)->opt), 0, sizeof(IPCB(skb)->opt)); /* Ensure the IP header is present in headroom */ if (!pskb_may_pull(skb, hlen_orig)) goto ignore_tunnel; -- 2.53.0