android_kernel_motorola_sm6375/net/ipv6
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Eric Dumazet 7b94a33952
ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
[ Upstream commit 86ab3e55673a7a49a841838776f1ab18d23a67b5 ]

Sashiko AI-review observed:

  In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet
  where its cb contains an IPv4 inet_skb_parm. When skb is cloned into skb2
  and passed to icmp6_send(), it uses IP6CB(skb2).

  IP6CB interprets the IPv4 inet_skb_parm as an inet6_skb_parm. The cipso
  offset in inet_skb_parm.opt directly overlaps with dsthao in inet6_skb_parm
  at offset 18.

  If an attacker sends a forged ICMPv4 error with a CIPSO IP option, dsthao
  would be a non-zero offset. Inside icmp6_send(), mip6_addr_swap() is called
  and uses ipv6_find_tlv(skb, opt->dsthao, IPV6_TLV_HAO).

  This would scan the inner, attacker-controlled IPv6 packet starting at that
  offset, potentially returning a fake TLV without checking if the remaining
  packet length can hold the full 18-byte struct ipv6_destopt_hao.

  Could mip6_addr_swap() then perform a 16-byte swap that extends past the end
  of the packet data into skb_shared_info?

  Should the cb array also be cleared in ip6_err_gen_icmpv6_unreach() and
  ip6ip6_err() to prevent this?

This patch implements the first suggestion.

I am not sure if ip6ip6_err() needs to be changed.
A separate patch would be better anyway.

Fixes: ca15a078bd ("sit: generate icmpv6 error when receiving icmpv4 error")
Reported-by: Ido Schimmel <idosch@nvidia.com>
Closes: https://sashiko.dev/#/patchset/20260326155138.2429480-1-edumazet%40google.com
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Oskar Kjos <oskar.kjos@hotmail.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260326202608.2976021-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit c438ba010171b70bad22fc18b1d5bdc3627476e8)

Orabug: 39300930
CVE: CVE-2026-43038

Change-Id: I07e2f318a3c835d56aae6b5e68d8e8e3c7e4c493
Signed-off-by: Alok Tiwari <alok.a.tiwari@oracle.com>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-07-29 03:40:57 +06:00
..
ila UPSTREAM: net: Fix checksum update for ILA adj-transport 2026-02-01 20:44:57 -08:00
netfilter BACKPORT: net: Fix Kconfig indentation, continued 2026-02-01 20:39:45 -08:00
addrconf.c BACKPORT: net: release reference to inet6_dev pointer 2026-05-07 10:16:30 -04:00
addrconf_core.c ipv6: Ensure natural alignment of const ipv6 loopback and router addresses 2024-02-23 08:25:04 +01:00
addrlabel.c
af_inet6.c UPSTREAM: bpf: Add get{peer, sock}name attach types for sock_addr 2026-01-14 17:44:17 -08:00
ah6.c net: ipv6: fix field-spanning memcpy warning in AH output 2025-12-03 12:45:09 +01:00
anycast.c
calipso.c calipso: Fix null-ptr-deref in calipso_req_{set,del}attr(). 2025-06-27 11:02:57 +01:00
datagram.c
esp6.c
esp6_offload.c
exthdrs.c
exthdrs_core.c
exthdrs_offload.c
fib6_notifier.c
fib6_rules.c ip: fib_rules: Fetch net from fib_rule in fib[46]_rule_configure(). 2025-06-04 14:32:34 +02:00
fou6.c
icmp.c ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() 2026-07-29 03:40:57 +06:00
inet6_connection_sock.c
inet6_hashtables.c UPSTREAM: net: export inet_lookup_reuseport and inet6_lookup_reuseport 2026-01-14 18:13:18 -08:00
ip6_checksum.c
ip6_fib.c UPSTREAM: bpf: Enable bpf_iter targets registering ctx argument types 2026-01-14 17:41:40 -08:00
ip6_flowlabel.c
ip6_gre.c erspan: make sure erspan_base_hdr is present in skb->head 2024-04-13 12:51:36 +02:00
ip6_icmp.c This is the 5.4.299 stable release 2025-09-10 05:55:28 +00:00
ip6_input.c BACKPORT: bpf: Add socket assign support 2025-12-23 13:36:11 -08:00
ip6_offload.c ipv6: reject malicious packets in ipv6_gso_segment() 2025-08-28 16:21:22 +02:00
ip6_offload.h
ip6_output.c ipv6: prevent possible UAF in ip6_xmit() 2025-01-09 13:23:33 +01:00
ip6_tunnel.c ip6_tunnel: clear skb2->cb[] in ip4ip6_err() 2026-07-29 03:40:57 +06:00
ip6_udp_tunnel.c BACKPORT: net: Make locking in sock_bindtoindex optional 2026-01-14 17:48:07 -08:00
ip6_vti.c
ip6mr.c ipmr: convert /proc handlers to rcu_read_lock() 2024-12-14 19:44:33 +01:00
ipcomp6.c
ipv6_sockglue.c UPSTREAM: seg6: fix seg6_validate_srh() to avoid slab-out-of-bounds 2026-01-14 17:48:10 -08:00
Kconfig
Makefile
mcast.c
mcast_snoop.c
mip6.c
ndisc.c BACKPORT: net: change accept_ra_min_rtr_lft to affect all RA lifetimes 2026-05-07 10:16:30 -04:00
netfilter.c netfilter: bridge: Move specific fragmented packet to slow_path instead of dropping it 2025-06-27 11:02:46 +01:00
output_core.c
ping.c
proc.c
protocol.c
raw.c ipv6: np->rxpmtu race annotation 2025-12-03 12:45:13 +01:00
reassembly.c
route.c UPSTREAM: bpf: Refactor bpf_iter_reg to have separate seq_info member 2026-01-14 18:12:07 -08:00
seg6.c UPSTREAM: seg6: fix seg6_validate_srh() to avoid slab-out-of-bounds 2026-01-14 17:48:10 -08:00
seg6_hmac.c ipv6: sr: validate HMAC algorithm ID in seg6_hmac_info_add 2025-08-28 16:21:37 +02:00
seg6_iptunnel.c UPSTREAM: seg6: fix seg6_validate_srh() to avoid slab-out-of-bounds 2026-01-14 17:48:10 -08:00
seg6_local.c UPSTREAM: seg6: fix seg6_validate_srh() to avoid slab-out-of-bounds 2026-01-14 17:48:10 -08:00
sit.c
syncookies.c
sysctl_net_ipv6.c BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
tcp_ipv6.c BACKPORT: bpf: tcp: Add bpf_skops_hdr_opt_len() and bpf_skops_write_hdr_opt() 2026-01-14 18:12:18 -08:00
tcpv6_offload.c
tunnel6.c
udp.c UPSTREAM: Revert "udp: Improve load balancing for SO_REUSEPORT." 2026-01-14 18:13:13 -08:00
udp_impl.h
udp_offload.c UPSTREAM: udp: do not transition UDP GRO fraglist partial checksums to unnecessary 2025-03-10 16:20:02 +00:00
udplite.c
xfrm6_input.c xfrm: Preserve vlan tags for transport mode software GRO 2024-05-17 11:43:53 +02:00
xfrm6_output.c
xfrm6_policy.c xfrm6: check ip6_dst_idev() return value in xfrm6_get_saddr() 2024-07-05 09:08:22 +02:00
xfrm6_protocol.c
xfrm6_state.c
xfrm6_tunnel.c