Hello:
This series was applied to netdev/net-next.git (main)
by Jakub Kicinski [off-list ref]:
On Mon, 3 Aug 2026 14:25:00 +0300 you wrote:
The bridge implements IPv6 neighbour suppression by snooping Neighbour
Solicitation and Neighbour Advertisement messages, but it previously only
checked the ICMPv6 type and code before acting on them. This leaves it
open to acting on malformed or spoofed packets that any RFC 4861 compliant
node should reject, and the option parsing in br_nd_send() open-codes a
loop that has historically been a source of bugs.
[...]
Here is the summary with links:
- [net-next,v2,1/5] bridge: Use direct pointer in br_is_nd_neigh_msg()
https://git.kernel.org/netdev/net-next/c/2cad8e3d9d94
- [net-next,v2,2/5] ipv6: ndisc: Add ndisc_check_ns_na() validation helper
https://git.kernel.org/netdev/net-next/c/9dfa6cca8959
- [net-next,v2,3/5] bridge: Validate NS/NA messages using ndisc_check_ns_na()
https://git.kernel.org/netdev/net-next/c/18668f4747c9
- [net-next,v2,4/5] bridge: Linearize skb once the ND message type is validated
https://git.kernel.org/netdev/net-next/c/67b14d6e36cf
- [net-next,v2,5/5] bridge: Use ndisc_parse_options() to parse ND options in br_nd_send()
https://git.kernel.org/netdev/net-next/c/7445aaa9fe6d
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html