From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-pg1-f170.google.com (mail-pg1-f170.google.com [209.85.215.170]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BC43A331203 for ; Tue, 6 Oct 2026 03:51:21 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.215.170 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791258683; cv=none; b=W/Pv9XzYCHhexWahGJ4osqLVZ0ajwcBh1qyciNvx1PCMDPFCp1vFoZCpV8YLdj+6Mg0nyiddpPQJ9hcWpDsmPE6w0yO9pitGll8WdZiBtvQ8/tjIOHhZ35gthfuzDegfbCg6gUQvjwm3sSiNR647Zuixf3mFiwOgN3wZP4XrM4w= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1791258683; c=relaxed/simple; bh=Ir+3VZ2zUPJJ2Bpgho/LS59fIOQGtDWwRnbNY1NTsgo=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version:Content-Type; b=gTcDrysmeTB8iZgp71CuBsqhdmKdw6Uf8aB1Qr/lGU2uwW/0VK+MX5hQyhXADr/NelY5Ij6l1jnI9Nm/M9iEAtgInAFWUJbTzxR4Jaw6xj5i44v+soaduQTKXqmu5/v1Fhdg3llWkn8P/W9AQpRaxuPQlAy1vqx4guppWV3RH3c= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com; spf=pass smtp.mailfrom=gmail.com; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b=ZawFPgLL; arc=none smtp.client-ip=209.85.215.170 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=gmail.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=gmail.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=gmail.com header.i=@gmail.com header.b="ZawFPgLL" Received: by mail-pg1-f170.google.com with SMTP id 41be03b00d2f7-cbe6295f05bso170496a12.1 for ; Mon, 05 Oct 2026 20:51:21 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1791258681; x=1791863481; darn=vger.kernel.org; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:from:to:cc:subject:date:message-id:reply-to :content-type; bh=fRiw2Vgxh1YIHzRLkUmzeJDin7CCSX1G4+FoDmEDtqw=; b=ZawFPgLLNuVLd4DMGjFRg7yd/3mfW4gJA5gvqfbXL4gZBgv2dU1uom9Gr3Ee9Bw+WY m/NPiwzjjNDnA1PtqyyM6cwpbnwT7mABnMAsIYuPPmQRzwXvzXMnRwuj4YiL1Q0xlmvy 9EsUvH1vQQ2T0wezF65oOH3XGIgcH1UdG/WO+sZhMZiSX6um25rXjot93keVNvoRLTwt vdgnpWImjY0vDL8ZuaD6MhL2DVnCexpOQahgf0e2ZbJIyPxYp/cEDbL3VWUI6zA4vGnO 5a6jRw1xsV1UJJAWaMssz4Ukps80MBJQ3o/1EuF8WxpTCJ/2TB6ClrlN2kYneU8gokGs TFQA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20260707; t=1791258681; x=1791863481; h=content-transfer-encoding:content-type:mime-version:message-id:date :subject:cc:to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject :date:message-id:reply-to:content-type; bh=fRiw2Vgxh1YIHzRLkUmzeJDin7CCSX1G4+FoDmEDtqw=; b=2G1pvl4Q+732Ao7GXyOQfC6MUImRQ9HvuOY5wegsFSAcEC6cJevfyxMhkPC+HFbV5b wvfp1FSEH+ipjBy0KuHDQ9gacKOj39OWUxBaqadmO7fP8v2HsNvUF3IQeKfmG5poM4YH 5WAMzjAXf9R3DVp25YD9+C0hKjHKmOVTDZlV6/dUnkH2MQO1oK4RJxdM9s9PfUaK9rit Hl5bPEXKn0GtdCbxsvzsFMq2QTu8PBonY3lZsBezxpyIaXyoqka1M+Eyt2cmaciTit9E KA4nJ0+vCmzqwhj+kNcajyGjOi+M8sEset5xxXkvQRuNCnDRyD0s031NUlfenCxsINRT 8rUQ== X-Forwarded-Encrypted: i=1; AKwUvByrDMD5y755H88j6Us4teepUlfq41v4VqFth9K07waayWJDAZ0WV8aZzSWo5nA5kCSgxeKp9+lIMDbJZus=@vger.kernel.org X-Gm-Message-State: AFq9FYKmEHwJsEECnYUmBC6epmpkrGLUTb5CS9Ilb/iFTClQh9s46Zg2 mUxYRh1EIsS4z1e0NOXkAi7P1V/UEo/dnT4M+8mtCAJwJW05Lg7e0bgb X-Gm-Gg: AYBFou0OO3ZYzuL2IipT/fAqOwkXx7GaNulyetGGNNfD3BBvSzEBntSJk+DDSB5qZxn JjZlsquZNGYBUBvc62U7NCwvWaV3zbVUR3N/HReygHV+QSebhDnhMps+zlzk/Xn1x30H2nH3hBj OyaMmFmmD+yFbnv93d80A5mrmGrbT2eGvEicw/IZJu5MUX6pakaz8IscKILLlJiJ2RluuAbH16u sxbTML6ZsFyx9YgLICX1A2IJazzfeywYIW8vVGCS6PAnhWiApxs1xTJcxFX+izaooB7lKdXIZXp 3YNx23K+/7vVdk8T9TtYaNZ05iastNg1KhR8gpbn3rxsHwWDAP80i+eh/Q19SHnvUOYXJK0goaW kG8caSjqtcDYHHe5on12LNVZU2eOhQhX+hFfJNJPVrMWNtIHmH3a8bWRYcnywHVvA4haBdI942I LupKnasbad25tDrxo22jVfbS9l4nSvuLgNcdVneWAqK28t0w15JrwVgxApN47/niI1UDMhGjISG /xJukCth4U= X-Received: by 2002:a17:90b:1c0c:b0:3a6:d30f:4658 with SMTP id 98e67ed59e1d1-3a8545cfef5mr981532a91.27.1791258680963; Mon, 05 Oct 2026 20:51:20 -0700 (PDT) Received: from ancienth-X870E-Nova-WiFi ([125.186.72.2]) by smtp.gmail.com with ESMTPSA id d9443c01a7336-2e5a5f001d9sm15634005ad.79.2026.10.05.20.51.17 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 05 Oct 2026 20:51:20 -0700 (PDT) From: Daehyeon Ko <4ncienth@gmail.com> To: Paul Moore , =?UTF-8?q?Ondrej=20Mosn=C3=A1=C4=8Dek?= Cc: "David S . Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , netdev@vger.kernel.org, linux-security-module@vger.kernel.org, linux-kernel@vger.kernel.org, Daehyeon Ko <4ncienth@gmail.com> Subject: [PATCH net v2] cipso: adjust cached option offsets when removing CIPSO Date: Tue, 6 Oct 2026 12:51:08 +0900 Message-ID: <20261006035108.3101440-1-4ncienth@gmail.com> X-Mailer: git-send-email 2.55.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit cipso_v4_skbuff_delattr() removes the CIPSO bytes but does not adjust cached offsets for options that follow them. For example, with a valid 10-byte CIPSO option followed by a seven-byte RR option, parsing records rr at offset 30. Removing CIPSO moves RR to offset 20, while the cached offset remains 30. Consumers such as ip_forward_options() and __ip_options_echo() then access the wrong bytes; the latter may interpret packet data as the option length and copy it into fixed-size option storage. Mirror cipso_v4_delopt() and subtract cipso_len from the srr, rr, ts and router_alert offsets when they follow CIPSO. cipso_len is the distance the first memmove() shifts those options. The later header move and network-header reset relocate the bytes and their offset base together. Fixes: 89aa3619d141 ("cipso: make cipso_v4_skbuff_delattr() fully remove the CIPSO options") Cc: stable@vger.kernel.org Reviewed-by: Ondrej Mosnáček Assisted-by: LLM Signed-off-by: Daehyeon Ko <4ncienth@gmail.com> --- Changes in v2: - Replace the parser-invalid 8-byte example with a valid 10-byte one. - Move the offset updates beside the other option metadata updates. Link: https://lore.kernel.org/netdev/20260930140400.2955466-1-4ncienth@gmail.com/ net/ipv4/cipso_ipv4.c | 8 ++++++++ 1 file changed, 8 insertions(+) diff --git a/net/ipv4/cipso_ipv4.c b/net/ipv4/cipso_ipv4.c index a05aa075de1a5b..1aacbbeffbc647 100644 --- a/net/ipv4/cipso_ipv4.c +++ b/net/ipv4/cipso_ipv4.c @@ -2287,6 +2287,14 @@ int cipso_v4_skbuff_delattr(struct sk_buff *skb) new_hdr_len - new_hdr_len_actual); opt->optlen -= hdr_len_delta; + if (opt->srr > opt->cipso) + opt->srr -= cipso_len; + if (opt->rr > opt->cipso) + opt->rr -= cipso_len; + if (opt->ts > opt->cipso) + opt->ts -= cipso_len; + if (opt->router_alert > opt->cipso) + opt->router_alert -= cipso_len; opt->cipso = 0; opt->is_changed = 1; if (hdr_len_delta != 0) { base-commit: d5a007b9b457c915ab1a53227e8939e4018aa97a -- 2.55.0