android_kernel_motorola_sm6375/net
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Eric Dumazet 7b94a33952
ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach()
[ Upstream commit 86ab3e55673a7a49a841838776f1ab18d23a67b5 ]

Sashiko AI-review observed:

  In ip6_err_gen_icmpv6_unreach(), the skb is an outer IPv4 ICMP error packet
  where its cb contains an IPv4 inet_skb_parm. When skb is cloned into skb2
  and passed to icmp6_send(), it uses IP6CB(skb2).

  IP6CB interprets the IPv4 inet_skb_parm as an inet6_skb_parm. The cipso
  offset in inet_skb_parm.opt directly overlaps with dsthao in inet6_skb_parm
  at offset 18.

  If an attacker sends a forged ICMPv4 error with a CIPSO IP option, dsthao
  would be a non-zero offset. Inside icmp6_send(), mip6_addr_swap() is called
  and uses ipv6_find_tlv(skb, opt->dsthao, IPV6_TLV_HAO).

  This would scan the inner, attacker-controlled IPv6 packet starting at that
  offset, potentially returning a fake TLV without checking if the remaining
  packet length can hold the full 18-byte struct ipv6_destopt_hao.

  Could mip6_addr_swap() then perform a 16-byte swap that extends past the end
  of the packet data into skb_shared_info?

  Should the cb array also be cleared in ip6_err_gen_icmpv6_unreach() and
  ip6ip6_err() to prevent this?

This patch implements the first suggestion.

I am not sure if ip6ip6_err() needs to be changed.
A separate patch would be better anyway.

Fixes: ca15a078bd ("sit: generate icmpv6 error when receiving icmpv4 error")
Reported-by: Ido Schimmel <idosch@nvidia.com>
Closes: https://sashiko.dev/#/patchset/20260326155138.2429480-1-edumazet%40google.com
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Oskar Kjos <oskar.kjos@hotmail.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/20260326202608.2976021-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
(cherry picked from commit c438ba010171b70bad22fc18b1d5bdc3627476e8)

Orabug: 39300930
CVE: CVE-2026-43038

Change-Id: I07e2f318a3c835d56aae6b5e68d8e8e3c7e4c493
Signed-off-by: Alok Tiwari <alok.a.tiwari@oracle.com>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-07-29 03:40:57 +06:00
..
6lowpan
9p net/9p: fix double req put in p9_fd_cancelled 2025-10-29 13:59:54 +01:00
802 net: 802: LLC+SNAP OID:PID lookup on start of skb data 2025-02-01 18:18:45 +01:00
8021q net: vlan: sync VLAN features with lower device 2025-12-03 12:45:15 +01:00
appletalk net: appletalk: Fix use-after-free in AARP proxy probe 2025-08-28 16:21:17 +02:00
atm net: atm: fix memory leak in atm_register_sysfs when device_register fail 2025-09-09 18:43:58 +02:00
ax25 BACKPORT: net: Make sock protocol value checks more specific 2025-12-23 13:35:52 -08:00
batman-adv batman-adv: fix OOB read/write in network-coding decode 2025-09-09 18:43:59 +02:00
bluetooth This is the 5.4.302 stable release 2025-12-11 09:41:30 +00:00
bpf UPSTREAM: bpf: Move skb->len == 0 checks into __bpf_redirect 2026-01-14 18:13:04 -08:00
bpfilter UPSTREAM: net/bpfilter: Initialize pos in __bpfilter_process_sockopt 2026-02-01 20:44:55 -08:00
bridge Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4 into android13-5.4-lahaina 2026-04-30 20:46:30 +03:00
caif This is the 5.4.297 stable release 2025-09-02 10:52:40 +00:00
can This is the 5.4.300 stable release 2025-10-02 13:53:47 +00:00
ceph libceph: fix race between delayed_work() and ceph_monc_stop() 2024-07-18 11:40:55 +02:00
core net: skbuff: fix missing zerocopy reference in pskb_carve helpers 2026-07-29 03:40:57 +06:00
dcb
dccp net: fix data-races around sk->sk_forward_alloc 2025-02-01 18:18:52 +01:00
decnet
dns_resolver
dsa net: dsa: microchip: linearize skb for tail-tagging switches 2025-09-09 18:44:00 +02:00
embms_kernel
ethernet ethernet: Add helper for assigning packet type when dest address does not match device address 2024-05-02 16:18:36 +02:00
hsr
ieee802154 net: ieee802154: do not leave a dangling sk pointer in ieee802154_create() 2024-12-14 19:44:51 +01:00
ife
ipv4 tcp: fix an incorrect __user annotation on tcp_use_userconfig_sysctl_handler 2026-07-29 03:30:09 +06:00
ipv6 ipv6: icmp: clear skb2->cb[] in ip6_err_gen_icmpv6_unreach() 2026-07-29 03:40:57 +06:00
iucv s390/iucv: fix receive buffer virtual vs physical address confusion 2024-09-04 13:14:57 +02:00
kcm kcm: Serialise kcm_sendmsg() for the same socket. 2024-09-04 13:14:59 +02:00
key
l2tp Revert "genetlink: hold RCU in genlmsg_mcast()" 2024-11-09 16:39:42 +00:00
l3mdev
lapb
llc llc: fix data loss when reading from a socket in llc_ui_recvmsg() 2025-06-04 14:32:35 +02:00
mac80211 Merge android11-5.4.302(91d385eb) into msm-5.4 2026-01-30 11:41:11 +05:30
mac802154 This is the 5.4.290 stable release 2025-02-05 17:00:16 +00:00
mpls BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
ncsi net: ncsi: Fix buffer overflow in fetching version id 2025-08-28 16:21:27 +02:00
netfilter Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4 into android13-5.4-lahaina 2026-04-30 20:46:30 +03:00
netlabel calipso: unlock rcu before returning -EAFNOSUPPORT 2025-06-27 11:02:50 +01:00
netlink UPSTREAM: bpf: Refactor bpf_iter_reg to have separate seq_info member 2026-01-14 18:12:07 -08:00
netrom netrom: check buffer length before accessing it 2025-01-09 13:23:35 +01:00
neuron
nfc BACKPORT: net: Fix Kconfig indentation, continued 2026-02-01 20:39:45 -08:00
nsh nsh: Restore skb->{protocol,data,mac_header} for outer header in nsh_gso_segment(). 2024-05-17 11:43:49 +02:00
openvswitch net: openvswitch: remove never-working support for setting nsh fields 2025-12-03 12:45:20 +01:00
packet net: fix fanout UAF in packet_release() via NETDEV_UP race 2026-07-29 03:40:57 +06:00
phonet BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
psample
qrtr Merge android11-5.4.289(4c8fb32) into msm-5.4 2025-03-26 11:56:22 +05:30
rds BACKPORT: tcp: add tcp_sock_set_keepidle 2026-01-14 17:50:47 -08:00
rfkill BACKPORT: compat_ioctl: move more drivers to compat_ptr_ioctl 2026-05-08 21:46:20 +02:00
rose rose: fix dangling neighbour pointers in rose_rt_device_down() 2025-07-17 18:25:00 +02:00
rxrpc rxrpc: Fix oops due to non-existence of prealloc backlog struct 2025-07-17 18:25:02 +02:00
sched Merge android11-5.4.302(91d385eb) into msm-5.4 2026-01-30 11:41:11 +05:30
sctp Revert "net, sctp, filter: remap copy_from_user failure error" 2026-02-01 20:44:59 -08:00
smc net/smc: check sndbuf_space again after NOSPACE flag is set in smc_poll 2025-01-09 13:23:27 +01:00
strparser strparser: Fix signed/unsigned mismatch bug 2025-12-03 12:45:19 +01:00
sunrpc BACKPORT: tcp: add tcp_sock_set_keepidle 2026-01-14 17:50:47 -08:00
switchdev
tipc This is the 5.4.302 stable release 2025-12-11 09:41:30 +00:00
tls UPSTREAM: net, sk_msg: Annotate lockless access to sk_prot on clone 2025-12-23 13:36:03 -08:00
unix af_unix: Remove put_pid()/put_cred() in copy_peercred(). 2024-09-12 11:03:52 +02:00
vmw_vsock This is the 5.4.302 stable release 2025-12-11 09:41:30 +00:00
wimax
wireless Revert "wifi: cfg80211: Increase akm_suites array size in" 2026-05-05 20:02:19 +03:00
x25
xdp UPSTREAM: bpf: Allow for map-in-map with dynamic inner array map entries 2026-01-14 18:12:44 -08:00
xfrm BACKPORT: net: Fix Kconfig indentation, continued 2026-02-01 20:39:45 -08:00
compat.c BACKPORT: net: simplify cBPF setsockopt compat handling 2026-01-14 18:12:33 -08:00
Kconfig BACKPORT: bpf: Clean up sockmap related Kconfigs 2026-02-01 20:44:37 -08:00
Makefile
OWNERS
socket.c
sysctl_net.c
TEST_MAPPING