From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-ej1-f48.google.com (mail-ej1-f48.google.com [209.85.218.48]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id BE1BF42EECE for ; Fri, 31 Jul 2026 15:24:16 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.218.48 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785511460; cv=none; b=r2YbH5sC4SnnoUdZIENa4Y1ecjxZBpIqPibL3FZNOlz3VakhTZNHBBjyHbOfbJ4UJYmViHGWwtvTMtkLi5aqJaoGIfqQfwAsii+km/Dj+QctRJvkAT1P1fSwjQmw/vPSYEMuYJyfgsGmToge6REh+P2fWQTvb2UJJ5xbPgP1nGo= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1785511460; c=relaxed/simple; bh=AnT9ykHGRiW9ML8tMoivB2MPdOWSnpohAXTeRpl5nGo=; h=Message-ID:Date:MIME-Version:Subject:To:Cc:References:From: In-Reply-To:Content-Type; b=AreGb9UiZfEArRIGWXJLKGNdcZoN8KBrrMRDHltIDtrQlTs1DwMdgNHJNJft6GqAZ2clOwdlkk1usrK/oLbvkKCStEPBBkiK8rsWGcPZDddUl45mhYrQU4OHIvKw2p39F/nPz0XhWWliBvvGlQnTY9pN5Fy201OqyBO9X5YoMbw= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=6wind.com; spf=pass smtp.mailfrom=6wind.com; dkim=pass (2048-bit key) header.d=6wind.com header.i=@6wind.com header.b=bQHhVxLy; arc=none smtp.client-ip=209.85.218.48 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=none dis=none) header.from=6wind.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=6wind.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=6wind.com header.i=@6wind.com header.b="bQHhVxLy" Received: by mail-ej1-f48.google.com with SMTP id a640c23a62f3a-c16879184e7so11561666b.3 for ; Fri, 31 Jul 2026 08:24:16 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=6wind.com; s=google; t=1785511453; x=1786116253; darn=vger.kernel.org; h=content-transfer-encoding:content-type:in-reply-to:organization :content-language:from:references:cc:to:subject:reply-to:user-agent :mime-version:date:message-id:from:to:cc:subject:date:message-id :reply-to:content-type; bh=iG6P15z3YvY8fxNxjEcOAHCU39JcDX4FjPan6Psmb9Y=; b=bQHhVxLyEdTxV+yonELQS0YOh82LjULmV7bkj8RRWRxxm1PHrTV4xv6M8K6onLPGTb zhopTlaxKlhb1jnDTGcqJ2FdNjNAetJUfnnZ0Dk1/DBFmQ3xHAUlNgmHg41OzVb8500j 2eC7d4jGJWiKY/dDM6GEqw3GHnWc/HZvEcROGOFNZsW9ZkBej25dLct0gbCkxioxwJu5 0sBiWgd8Gt1IUpLhU8XPKb3GmXovJp4NejD7TACE8cULeiwhxEUL2as9ETsfO/tQtEvJ 4o0IR5EMQFU6SFIuzi32QLBnwpSykP5zyBvG7qWo/N7vaN4JJ1KOgT+UVVgmyesgFsEk 466g== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785511453; x=1786116253; h=content-transfer-encoding:content-type:in-reply-to:organization :content-language:from:references:cc:to:subject:reply-to:user-agent :mime-version:date:message-id:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=iG6P15z3YvY8fxNxjEcOAHCU39JcDX4FjPan6Psmb9Y=; b=Xtz0DIY5AGVNuid21tPWGwb8eCj2AU4OYVWFsqvSZaIWE+lHgqjsd0HWbBJf7VmKHI GnDvy6sHikfK4mBEmglKk9FuXSqKpvMqFpOeP+MP8KR9a5xSUlov9OxhAQ/W1Tu4sKKg hASJZOBF6H/CaC+1Efvl0oFeW+fB0MCkeoT4vQ8eyGNhEmPdCaFBVpeVRsf1nJN2os0v UFw8IJPYTN1IaESwr8K95Y7a/GbMPb1PL177Izrn+t68OgXM+EOiPsG6pDdFpghO8lJP fd+b9vX0z0BrFpH5zJU/lmvyiVdIQdCTEHL1B/kzPO9MKXXxBHwOr6rJMezP01g7aeXL g8Rg== X-Forwarded-Encrypted: i=1; AHgh+RpYjcuLWa+29KPZT4MEQXCUi2KrCgotKOYpkTOaEIZD0n7ZJZT/4+Rc+dkxj+83Su6gVC2H9EcQ2KU5lNU=@vger.kernel.org X-Gm-Message-State: AOJu0YyoE4n51vna3JEhr6yM+zOVJyINPKOO9d2s0LI9u/rK/6t4AX3Q a7MUkNOKCqZsXfVGLeeUORMuzPE2RST1HgoW86FMYU+ZkJKeCAEiC6SRJBa6Yg88Mnw= X-Gm-Gg: AR+sD12HBbeWpwRxWk4lppEWhAnJEO0Dyr1PwDpJig3YzZ6I9Kp64pnBWSqD+estx+f IZO4AIzMJOo0S7UM7CFvbAulXnHVJlYp+Bq3WJ8gwwcZc8E8Raaylk7XmWhJEhMP82ys365YbYl GTTlQ2DQkgwVoRfwQAMI5oYotYNNctSlvFyXTu/ws0PnnL3kWeaDCvv40+DGl+xj0ISPVWDboxA wWgAReStFqQTvCoOUzvqg3LU2TeedabZ1Hyp06KZQA/HoAiR5wJ6SehC11GGZNnAl/F0u8Sf/mO W9m4LKra8qr9DutRGibjwqVM9WYimVBdE4WSYTWg1mB2P9hnOqdRXj/4NA6o98MecEMb+aCv9fr cDnHZFfsnc/iqMR4eVvmmQWBTr26uEyDbKHnvavb8/PKPZpFZbVPe635iMgSLSWlSnrgAToMlvm qcGYlDawZCLZOckPdHHe6RdwzWvbtyrDCXou9A3gSM823dDdtqwnqbTGAmGpNJ09V+1saRH3WoD 0cUvd6WEvHwPRCiXSsVEcua8HldAJEspiwff1lLZA== X-Received: by 2002:a17:907:8749:b0:c16:1290:11a7 with SMTP id a640c23a62f3a-c1fe7c5fb22mr12970066b.1.1785511453406; Fri, 31 Jul 2026 08:24:13 -0700 (PDT) Received: from ?IPV6:2a01:e0a:ab7:2110:6a1d:efff:fe52:1959? ([2a01:e0a:ab7:2110:6a1d:efff:fe52:1959]) by smtp.gmail.com with ESMTPSA id a640c23a62f3a-c1fd445449asm175813866b.37.2026.07.31.08.24.12 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Fri, 31 Jul 2026 08:24:12 -0700 (PDT) Message-ID: <6eec5c20-88d2-4a82-84ff-da0d5ceb3905@6wind.com> Date: Fri, 31 Jul 2026 17:24:11 +0200 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 User-Agent: Mozilla Thunderbird Reply-To: nicolas.dichtel@6wind.com Subject: Re: [PATCH] ipv6: seg6: clear IPv4 control block in End.DT4 To: David Lee , andrea.mayer@uniroma2.it, davem@davemloft.net, edumazet@google.com, kuba@kernel.org, pabeni@redhat.com Cc: Kyle Zeng , Dominik 'Disconnect3d' Czarnota , horms@kernel.org, netdev@vger.kernel.org, linux-kernel@vger.kernel.org References: <20260731140832.567669-1-david.lee@trailofbits.com> From: Nicolas Dichtel Content-Language: en-US Organization: 6WIND In-Reply-To: <20260731140832.567669-1-david.lee@trailofbits.com> Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Le 31/07/2026 à 16:08, David Lee a écrit : > The End.DT4 input path decapsulates an IPv4 packet and sends it > directly to ip_route_input() and dst_input(). It therefore bypasses > ip_rcv_core(), which normally clears IPCB. The skb still contains > IP6CB data from the outer packet, and IPv6 extension-header offsets > overlap the IPv4 option fields. This can make __ip_options_echo() > copy beyond the allocation for saved options. > > Clear IPCB after validating the inner IPv4 header and preserve the > ingress interface as ip_rcv_core() does. This prevents outer IPv6 > metadata from being interpreted as inner IPv4 options. > > Fixes: 664d6f86868b ("seg6: add support for the SRv6 End.DT4 behavior") > Bug found and triaged by OpenAI Security Research and > validated by Trail of Bits. There should be no empty line between tags. > > Assisted-by: Codex:gpt-5.6-sol gpt-5.5-cyber > Signed-off-by: Kyle Zeng > --- > Trail of Bits has a reproducer for this bug that triggers a KASAN > slab-out-of-bounds write in __ip_options_echo() and can share if needed. > > net/ipv6/seg6_local.c | 3 +++ > 1 file changed, 3 insertions(+) > > diff --git a/net/ipv6/seg6_local.c b/net/ipv6/seg6_local.c > index 2b41e4c0d..d03b377f5 100644 > --- a/net/ipv6/seg6_local.c > +++ b/net/ipv6/seg6_local.c > @@ -1186,6 +1186,9 @@ static int input_action_end_dt4(struct sk_buff *skb, > if (!pskb_may_pull(skb, sizeof(struct iphdr))) > goto drop; > > + memset(IPCB(skb), 0, sizeof(*IPCB(skb))); > + IPCB(skb)->iif = skb->skb_iif; > + > skb = end_dt_vrf_core(skb, slwt, AF_INET); > if (!skb) > /* packet has been processed and consumed by the VRF */ > End.DX4 also calls ip_route_input(). I guess the same problem exists. Am I wrong? Regards, Nicolas