Re: [PATCH net 8/9] ipvs: fix more places with wrong ipv6 transport offsets

Paolo Abeni <[email protected]> Fri, 17 Jul 2026 11:17:15 +0200
Newsgroups gmane.linux.network,gmane.comp.security.firewalls.netfilter.devel
Message-ID <[email protected]>
Hi,

On 7/10/26 4:37 PM, Florian Westphal wrote:
> From: Julian Anastasov <[email protected]>
> 
> Sashiko reports for more incorrect IPv6 transport offsets.
> 
> The app code for TCP was assuming IPv4 network header
> even after the ipvsh argument was provided. This can
> cause problems with apps over IPv6. As for the only
> official app in the kernel tree (FTP) this problem is
> harmless because we use Netfilter to mangle the FTP
> ports and we do not adjust the TCP seq numbers.
> 
> Also, provide correct offset of the ICMPV6 header in
> ip_vs_out_icmp_v6() for correct checksum checks when
> the IPv6 packet has extension headers.
> 
> Fixes: d12e12299a69 ("ipvs: add ipv6 support to ftp")
> Fixes: 2a3b791e6e11 ("IPVS: Add/adjust Netfilter hook functions and helpers for v6")
> Cc: [email protected]
> Link: https://sashiko.dev/#/patchset/20260706101624.69471-1-zhaoyz24%40mails.tsinghua.edu.cn
> Signed-off-by: Julian Anastasov <[email protected]>
> Signed-off-by: Florian Westphal <[email protected]>
> ---
>  net/netfilter/ipvs/ip_vs_app.c  | 10 ++++------
>  net/netfilter/ipvs/ip_vs_core.c |  3 +--
>  2 files changed, 5 insertions(+), 8 deletions(-)
> 
> diff --git a/net/netfilter/ipvs/ip_vs_app.c b/net/netfilter/ipvs/ip_vs_app.c
> index d54d7da58334..b0e00be85cb1 100644
> --- a/net/netfilter/ipvs/ip_vs_app.c
> +++ b/net/netfilter/ipvs/ip_vs_app.c
> @@ -361,14 +361,13 @@ static inline int app_tcp_pkt_out(struct ip_vs_conn *cp, struct sk_buff *skb,
>  				  struct ip_vs_iphdr *ipvsh)
>  {
>  	int diff;
> -	const unsigned int tcp_offset = ip_hdrlen(skb);
>  	struct tcphdr *th;
>  	__u32 seq;
>  
> -	if (skb_ensure_writable(skb, tcp_offset + sizeof(*th)))
> +	if (skb_ensure_writable(skb, ipvsh->len + sizeof(*th)))
>  		return 0;
>  
> -	th = (struct tcphdr *)(skb_network_header(skb) + tcp_offset);
> +	th = (struct tcphdr *)(skb_network_header(skb) + ipvsh->len);

Beyond the usual set of pre-existing issues, sashiko-gemini noted this
patch may need a follow-up:

https://sashiko.dev/#/patchset/20260710143733.29741-2-fw%40strlen.de

/P