Thread (11 messages) flat view 11 messages, 3 authors, 6d ago

Re: [PATCH net-next v2 0/5] bridge: Validate and clean up IPv6 neighbour suppression

From: patchwork-bot+netdevbpf@kernel.org
Date: 2026-08-07 23:41:03
Also in: bridge, lkml

Hello:

This series was applied to netdev/net-next.git (main)
by Jakub Kicinski [off-list ref]:

On Mon, 3 Aug 2026 14:25:00 +0300 you wrote:
The bridge implements IPv6 neighbour suppression by snooping Neighbour
Solicitation and Neighbour Advertisement messages, but it previously only
checked the ICMPv6 type and code before acting on them. This leaves it
open to acting on malformed or spoofed packets that any RFC 4861 compliant
node should reject, and the option parsing in br_nd_send() open-codes a
loop that has historically been a source of bugs.

[...]
Here is the summary with links:
  - [net-next,v2,1/5] bridge: Use direct pointer in br_is_nd_neigh_msg()
    https://git.kernel.org/netdev/net-next/c/2cad8e3d9d94
  - [net-next,v2,2/5] ipv6: ndisc: Add ndisc_check_ns_na() validation helper
    https://git.kernel.org/netdev/net-next/c/9dfa6cca8959
  - [net-next,v2,3/5] bridge: Validate NS/NA messages using ndisc_check_ns_na()
    https://git.kernel.org/netdev/net-next/c/18668f4747c9
  - [net-next,v2,4/5] bridge: Linearize skb once the ND message type is validated
    https://git.kernel.org/netdev/net-next/c/67b14d6e36cf
  - [net-next,v2,5/5] bridge: Use ndisc_parse_options() to parse ND options in br_nd_send()
    https://git.kernel.org/netdev/net-next/c/7445aaa9fe6d

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help