From: Star Chang <starchang@google.com>
To: netdev@vger.kernel.org
Cc: dsahern@kernel.org, edumazet@google.com, kuba@kernel.org,
pabeni@redhat.com, davem@davemloft.net,
linux-kernel@vger.kernel.org, wangroger@google.com,
Star Chang <starchang@google.com>
Subject: [PATCH net] net: Fix Hole-196 vulnerability by dropping unicast ARP/IP in L2 BMC
Date: Fri, 2 Oct 2026 08:23:36 +0000 [thread overview]
Message-ID: <20261002082336.608201-1-starchang@google.com> (raw)
Wi-Fi 802.11 to 802.3 frame translation allows attackers to inject
unicast L3 packets or ARP payloads inside GTK-encrypted L2 broadcast
and multicast (BMC) frames (the "Hole-196" vulnerability).
While the `drop_unicast_in_l2_multicast` sysctl was introduced to drop
unicast IPv4/IPv6 packets received over L2 BMC, it had several gaps:
1. ARP packets were not checked in `net/ipv4/arp.c`, allowing attackers
to perform ARP poisoning via L2 BMC frames (`group-arp-unicast`).
2. Enforcement lacked DHCP client (UDP port 68) exemption, which could
discard legitimate DHCP server responses sent via L2 broadcast.
3. Dropped packets were silently discarded without warnings or MIB stats.
Enhance `drop_unicast_in_l2_multicast` sysctl enforcement:
- Extend sysctl checks to `net/ipv4/arp.c` (`arp_process()`) to drop
unsolicited ARP Replies and ARP Requests with a non-zero unicast
Target Hardware Address (tha) received over L2 BMC.
- Exempt Gratuitous ARP (GARP) and RFC 5227 Address Announcements
(`sip == tip`) from L2 BMC unicast drop logic so they defer to the
`DROP_GRATUITOUS_ARP` sysctl, preserving VRRP/HSRP router failover.
- Exempt non-fragmented DHCP client traffic (UDP dest port 68) in
`net/ipv4/ip_input.c` and safely reload `ip_hdr(skb)` after
`pskb_may_pull()` to prevent dangling pointer access.
- Log rate-limited warnings (`pr_warn_ratelimited`) and increment MIB
error counters (`IPSTATS_MIB_INHDRERRORS`) for dropped frames.
Signed-off-by: Star Chang <starchang@google.com>
---
net/ipv4/arp.c | 29 +++++++++++++++++++++++++++++
net/ipv4/ip_input.c | 27 +++++++++++++++++++++++++--
net/ipv6/ip6_input.c | 2 ++
3 files changed, 56 insertions(+), 2 deletions(-)
diff --git a/net/ipv4/arp.c b/net/ipv4/arp.c
index d409f606aec0..ad23db2e2f59 100644
--- a/net/ipv4/arp.c
+++ b/net/ipv4/arp.c
@@ -791,6 +791,35 @@ static int arp_process(struct net *net, struct sock *sk, struct sk_buff *skb)
(!IN_DEV_ROUTE_LOCALNET(in_dev) && ipv4_is_loopback(tip)))
goto out_free_skb;
+/*
+ * Hole-196 defense for ARP:
+ * If drop_unicast_in_l2_multicast sysctl is enabled on this interface,
+ * drop ARP Replies in L2 BMC frames, and ARP Requests in L2 BMC frames
+ * that specify a non-zero unicast Target Hardware Address (tha).
+ *
+ * Legitimate Gratuitous ARP (GARP) and RFC 5227 Address Announcements
+ * require (sip == tip) and tha matching sha (tha == sha). Only valid
+ * GARP frames are exempted so they defer to DROP_GRATUITOUS_ARP below.
+ */
+ if ((skb->pkt_type == PACKET_BROADCAST ||
+ skb->pkt_type == PACKET_MULTICAST) &&
+ IN_DEV_ORCONF(in_dev, DROP_UNICAST_IN_L2_MULTICAST)) {
+ bool is_valid_garp = (sip == tip) && tha &&
+ !memcmp(tha, sha, dev->addr_len);
+
+ if (arp->ar_op == htons(ARPOP_REPLY) && !is_valid_garp) {
+ net_warn_ratelimited("Drop ARP Reply in L2 BMC on %s\n",
+ dev->name);
+ goto out_free_skb;
+ }
+ if (dev->addr_len == ETH_ALEN && tha &&
+ is_valid_ether_addr(tha) && !is_valid_garp) {
+ net_warn_ratelimited("Drop unicast THA ARP Req in L2 BMC on %s\n",
+ dev->name);
+ goto out_free_skb;
+ }
+ }
+
/*
* For some 802.11 wireless deployments (and possibly other networks),
* there will be an ARP proxy and gratuitous ARP frames are attacks
diff --git a/net/ipv4/ip_input.c b/net/ipv4/ip_input.c
index 9860178752b8..f863aa293020 100644
--- a/net/ipv4/ip_input.c
+++ b/net/ipv4/ip_input.c
@@ -456,10 +456,33 @@ static int ip_rcv_finish_core(struct net *net,
* this is 802.11 protecting against cross-station spoofing (the
* so-called "hole-196" attack) so do it for both.
*/
+ /* Hole-196 defense:
+ * Drop unicast IP packets received over L2 BMC frames.
+ * Exempt DHCP client responses (UDP port 68).
+ */
if (in_dev &&
IN_DEV_ORCONF(in_dev, DROP_UNICAST_IN_L2_MULTICAST)) {
- drop_reason = SKB_DROP_REASON_UNICAST_IN_L2_MULTICAST;
- goto drop;
+ bool is_dhcp_resp = false;
+
+ iph = ip_hdr(skb);
+ if (iph->protocol == IPPROTO_UDP && !ip_is_fragment(iph) &&
+ pskb_may_pull(skb, iph->ihl * 4 + sizeof(struct udphdr))) {
+ const struct udphdr *uh;
+
+ iph = ip_hdr(skb);
+ uh = (const struct udphdr *)(skb_network_header(skb) +
+ iph->ihl * 4);
+ if (uh->dest == htons(68))
+ is_dhcp_resp = true;
+ }
+
+ if (!is_dhcp_resp) {
+ net_warn_ratelimited("Drop unicast IP %pI4 in L2 BMC on %s\n",
+ &iph->daddr, dev->name);
+ __IP_INC_STATS(net, IPSTATS_MIB_INHDRERRORS);
+ drop_reason = SKB_DROP_REASON_UNICAST_IN_L2_MULTICAST;
+ goto drop;
+ }
}
}
diff --git a/net/ipv6/ip6_input.c b/net/ipv6/ip6_input.c
index 8972863c93ee..caf9811f6352 100644
--- a/net/ipv6/ip6_input.c
+++ b/net/ipv6/ip6_input.c
@@ -278,6 +278,8 @@ static struct sk_buff *ip6_rcv_core(struct sk_buff *skb, struct net_device *dev,
(skb->pkt_type == PACKET_BROADCAST ||
skb->pkt_type == PACKET_MULTICAST) &&
READ_ONCE(idev->cnf.drop_unicast_in_l2_multicast)) {
+ net_warn_ratelimited("IPv6: Drop unicast IP %pI6c in L2 BMC on %s\n",
+ &hdr->daddr, dev->name);
SKB_DR_SET(reason, UNICAST_IN_L2_MULTICAST);
goto err;
}
--
2.56.0.rc1.315.gc6ed9934b7-goog
next reply other threads:[~2026-10-02 8:23 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-02 8:23 Star Chang [this message]
2026-10-02 8:29 ` netdev-bot+sinfo
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20261002082336.608201-1-starchang@google.com \
--to=starchang@google.com \
--cc=davem@davemloft.net \
--cc=dsahern@kernel.org \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=wangroger@google.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®