Thread (6 messages) 6 messages, 3 authors, 7d ago

Re: [PATCH net v2] xfrm: validate ihl in xfrm4_transport_output()

From: Herbert Xu <herbert@gondor.apana.org.au>
Date: 2026-09-23 02:24:15
Also in: stable

On Wed, Sep 23, 2026 at 10:16:40AM +0800, Qihang wrote:
xfrm4_transport_output() reads the IPv4 header length (ihl) from the
packet and uses it for __skb_pull() and memmove() without validating it,
so a frame with ihl * 4 larger than the linear header underflows skb->len
to a huge value or trips BUG() in __skb_pull().

Packets injected into an xfrm interface (e.g. AF_PACKET on an xfrmi
device) reach xfrm output without the header validation that
ip_rcv_core() applies to received traffic.  The underflowed length then
flows into esp_output() and the crypto scatterlist setup, where every
length in the underflow window ends in a fatal fault (BUG_ON in
__skb_to_sgvec()).  This is a deterministic local denial of service
reachable by an unprivileged user through a user and network namespace.

Reject ihl < 5, matching ip_rcv_core(), so a complete IPv4 header is
present.  Then use pskb_may_pull() to make the header linear: this
rejects ihl > skb->len, linearizes a header that currently lives in
fragments, and guarantees __skb_pull()'s precondition that the pull must
not drive skb->len below skb->data_len, and it keeps the memmove() source
in bounds.  ip_hdr() is re-read afterwards because pskb_may_pull() may
reallocate the skb head.  xfrm6_transport_output() already bounds its
header length through xfrm6_hdr_offset().

Fixes: b59f45d0b2878 ("[IPSEC] xfrm: Abstract out encapsulation modes")
Cc: stable@vger.kernel.org
Signed-off-by: Qihang <redacted>
---
 net/xfrm/xfrm_output.c | 5 +++++
 1 file changed, 5 insertions(+)
As I said when this first came up, our entire IPv4 stack
assumes that this is validated upon entry into the IP stack.

So taking a whack-a-mole approach inside the IPv4 stack is the
wrong thing to do.

Please fix those entry points into the stack instead by ensuring
that the IP header is valid.

Thanks,
-- 
Email: Herbert Xu [off-list ref]
Home Page: http://gondor.apana.org.au/~herbert/
PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help