From: Pablo Neira Ayuso <pablo@netfilter.org>
To: 성병찬 <tjdqudcks0424@naver.com>
Cc: fw@strlen.de, phil@nwl.cc, netfilter-devel@vger.kernel.org,
netdev@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [BUG] netfilter: IPv6 conntrack fragment reassembly truncates header offset
Date: Tue, 29 Sep 2026 11:01:17 +0200 [thread overview]
Message-ID: <art-XRsR09GIvc4D@chamomile> (raw)
In-Reply-To: <31da96413a406da2116f44df2db84f@cweb009.nm>
Hi,
We have a patch for this.
But I stumbled a few times over it because I did not have a
reproducer.
If you can share it with me, that would great. Thanks.
On Tue, Sep 29, 2026 at 02:07:58PM +0900, 성병찬 wrote:
> Hello,
>
> I found a reproducible IPv6 conntrack fragment reassembly bug in:
>
> net/ipv6/netfilter/nf_conntrack_reasm.c
>
> Tested kernel:
>
> Linux v7.2.8
> commit: 9a66fdc0d7fd55f54235524a73435af99051e46f
> architecture: x86_64
> KASAN and KCOV enabled
>
> The problem appears to be in find_prev_fhdr():
>
> u8 prev_nhoff = netoff + offsetof(struct ipv6hdr, nexthdr);
>
> A valid IPv6 extension-header chain can place the previous Next Header
> field at offset 256. Since prev_nhoff is u8, the value is truncated from
> 256 to 0.
>
> The truncated value is later stored as the fragment queue nhoffset.
> During reassembly, nf_ct_frag6_reasm() consequently modifies byte 0 of
> the IPv6 header instead of the Next Header field at offset 256.
>
> Observed results with the unmodified kernel:
>
> - Control packet with predecessor offset 248: delivered
> - Boundary packet with predecessor offset 256: not delivered
> - Ip6InHdrErrors increased by 1
> - The result was reproduced twice
>
> I then changed the local variable from u8 to int:
>
> - u8 prev_nhoff;
> + int prev_nhoff;
>
> Observed results with the modified kernel:
>
> - Control packet: delivered
> - Boundary packet: delivered
> - Ip6InHdrErrors did not increase
> - The result was reproduced twice
>
> I also tested the boundary packet against an IPv6 INPUT firewall rule.
> The packet was counted by both ACCEPT and DROP rules, and no firewall
> bypass was observed.
>
> No KASAN report, memory corruption, information disclosure, privilege
> escalation, or firewall bypass was observed. I am therefore reporting
> this as a packet corruption/drop correctness bug, not as a confirmed
> security vulnerability.
>
> The same u8 declaration appears to remain in the current mainline
> source.
>
> The code appears to have originated from commit:
>
> 6b88dd966b42e374dc783c397efc15f5c1458265
> ("[SK_BUFF] ipv6: Use skb_network_offset in some more places")
>
> I have a minimal C reproducer, kernel configuration, serial logs, and
> before/after test results available. Please let me know if you would
> like me to send the reproducer or prepare a formal patch.
>
> Regards,
> sungbyeongchan
next parent reply other threads:[~2026-09-29 9:01 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
[not found] <31da96413a406da2116f44df2db84f@cweb009.nm>
2026-09-29 9:01 ` Pablo Neira Ayuso [this message]
2026-09-29 9:14 ` 성병찬
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=art-XRsR09GIvc4D@chamomile \
--to=pablo@netfilter.org \
--cc=fw@strlen.de \
--cc=linux-kernel@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=netfilter-devel@vger.kernel.org \
--cc=phil@nwl.cc \
--cc=tjdqudcks0424@naver.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®