Thread (3 messages) read the whole thread 3 messages, 2 authors, 9d ago

Re: [PATCH ipsec] xfrm: ah6: validate routing header segments_left

From: manizada <hidden>
Date: 2026-07-23 15:07:19




On Thursday, July 23rd, 2026 at 1:05 AM, Steffen Klassert [off-list ref] wrote:
On Tue, Jul 21, 2026 at 10:28:52PM +0000, Asim Viladi Oglu Manizada wrote:
quoted
AH6 rearranges routing-header addresses before computing or verifying the
ICV. ipv6_rearrange_rthdr() assumes that segments_left is not larger than
the number of addresses described by the routing header's hdrlen field.

That assumption does not hold for raw IPv6 HDRINCL packets. A packet with
hdrlen equal to 2 describes one address, but can carry an arbitrary
segments_left value. With segments_left equal to 255, the function moves
its address pointer 4,064 bytes backwards and passes a 4,064-byte length to
memmove(), resulting in an out-of-bounds access.

Validate the invariant locally before modifying the routing header or
performing any address-pointer arithmetic, and propagate malformed-header
errors to the existing AH6 input and output error paths.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Cc: stable@vger.kernel.org
Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
Signed-off-by: Asim Viladi Oglu Manizada <redacted>
---
 net/ipv6/ah6.c | 26 +++++++++++++++-----------
 1 file changed, 15 insertions(+), 11 deletions(-)
diff --git a/net/ipv6/ah6.c b/net/ipv6/ah6.c
index 76f7a2de9108..0f01db802f35 100644
--- a/net/ipv6/ah6.c
+++ b/net/ipv6/ah6.c
@@ -233,25 +233,24 @@ static void ipv6_rearrange_destopt(struct ipv6hdr *iph, struct ipv6_opt_hdr *des
  *	so that they appear in the order they will at the final destination.
  *	See Appendix A2 of RFC 2402 for details.
  */
-static void ipv6_rearrange_rthdr(struct ipv6hdr *iph, struct ipv6_rt_hdr *rthdr)
+static int ipv6_rearrange_rthdr(struct ipv6hdr *iph, struct ipv6_rt_hdr *rthdr)
You changed the return of this function from void to int. Please update
the comment on that function to reflect this. See:

https://netdev-ctrl.bots.linux.dev/logs/build/1131973/14702013/kdoc/summary
Thanks, this is now at https://lore.kernel.org/netdev/20260723093524.3672512-1-manizada@pm.me/ (local) 
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help