Thread (4 messages) flat view 4 messages, 4 authors, 9d ago

Re: [BUG] net/bridge: out-of-bounds in br_forward()

From: Nikolay Aleksandrov <razor@blackwall.org>
Date: 2026-08-27 14:35:54
Also in: bridge, lkml, netfilter-devel

On 27/08/2026 17:29, Florian Westphal wrote:
co [off-list ref] wrote:
quoted
We found a bug reachable in:

     path    net/bridge/netfilter
     crash   out-of-bounds in br_forward()
     commit  7b5344954050 ("Merge tag 'nf-26-08-10' of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf")
I'm looking into these reports, I think this is the same
underlying bug as the other report; a variant of

ccb9fd4b8753 ("netfilter: revalidate bridge ports")

That bug uses nfnetlink_queue for RCU escape, the other two reports
use defrag engine.

And sure, its br_netfilter again -- I think we will have to consider
removing it even though it will break existing setups.
+10
As a compromise, I suggest to reject br_netfilter in user namespaces,
i.e. call_iptables cannot be enabled anymore unless you have
CAP_NET_ADMIN in init net.
+1000 :)

I absolutely agree on both counts.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help