mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: Pablo Neira Ayuso <pablo@netfilter.org>
To: 성병찬 <tjdqudcks0424@naver.com>
Cc: fw@strlen.de, phil@nwl.cc, netfilter-devel@vger.kernel.org,
	netdev@vger.kernel.org, linux-kernel@vger.kernel.org
Subject: Re: [BUG] netfilter: IPv6 conntrack fragment reassembly truncates header offset
Date: Tue, 29 Sep 2026 11:01:17 +0200	[thread overview]
Message-ID: <art-XRsR09GIvc4D@chamomile> (raw)
In-Reply-To: <31da96413a406da2116f44df2db84f@cweb009.nm>

Hi,

We have a patch for this.

But I stumbled a few times over it because I did not have a
reproducer.

If you can share it with me, that would great. Thanks.

On Tue, Sep 29, 2026 at 02:07:58PM +0900, 성병찬 wrote:
> Hello,
> 
> I found a reproducible IPv6 conntrack fragment reassembly bug in:
> 
>   net/ipv6/netfilter/nf_conntrack_reasm.c
> 
> Tested kernel:
> 
>   Linux v7.2.8
>   commit: 9a66fdc0d7fd55f54235524a73435af99051e46f
>   architecture: x86_64
>   KASAN and KCOV enabled
> 
> The problem appears to be in find_prev_fhdr():
> 
>   u8 prev_nhoff = netoff + offsetof(struct ipv6hdr, nexthdr);
> 
> A valid IPv6 extension-header chain can place the previous Next Header
> field at offset 256. Since prev_nhoff is u8, the value is truncated from
> 256 to 0.
> 
> The truncated value is later stored as the fragment queue nhoffset.
> During reassembly, nf_ct_frag6_reasm() consequently modifies byte 0 of
> the IPv6 header instead of the Next Header field at offset 256.
> 
> Observed results with the unmodified kernel:
> 
>   - Control packet with predecessor offset 248: delivered
>   - Boundary packet with predecessor offset 256: not delivered
>   - Ip6InHdrErrors increased by 1
>   - The result was reproduced twice
> 
> I then changed the local variable from u8 to int:
> 
>   - u8 prev_nhoff;
>   + int prev_nhoff;
> 
> Observed results with the modified kernel:
> 
>   - Control packet: delivered
>   - Boundary packet: delivered
>   - Ip6InHdrErrors did not increase
>   - The result was reproduced twice
> 
> I also tested the boundary packet against an IPv6 INPUT firewall rule.
> The packet was counted by both ACCEPT and DROP rules, and no firewall
> bypass was observed.
> 
> No KASAN report, memory corruption, information disclosure, privilege
> escalation, or firewall bypass was observed. I am therefore reporting
> this as a packet corruption/drop correctness bug, not as a confirmed
> security vulnerability.
> 
> The same u8 declaration appears to remain in the current mainline
> source.
> 
> The code appears to have originated from commit:
> 
>   6b88dd966b42e374dc783c397efc15f5c1458265
>   ("[SK_BUFF] ipv6: Use skb_network_offset in some more places")
> 
> I have a minimal C reproducer, kernel configuration, serial logs, and
> before/after test results available. Please let me know if you would
> like me to send the reproducer or prepare a formal patch.
> 
> Regards,
> sungbyeongchan

       reply	other threads:[~2026-09-29  9:01 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
     [not found] <31da96413a406da2116f44df2db84f@cweb009.nm>
2026-09-29  9:01 ` Pablo Neira Ayuso [this message]
2026-09-29  9:14   ` 성병찬

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=art-XRsR09GIvc4D@chamomile \
    --to=pablo@netfilter.org \
    --cc=fw@strlen.de \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=netfilter-devel@vger.kernel.org \
    --cc=phil@nwl.cc \
    --cc=tjdqudcks0424@naver.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®