Re: [PATCH net] net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled

Fernando Fernandez Mancera <[email protected]>
Newsgroups gmane.linux.network.bridge,gmane.linux.network
Message-ID <[email protected]>
On 2/27/26 12:40 AM, Fernando Fernandez Mancera wrote:
> When booting with the 'ipv6.disable=1' parameter, the nd_tbl is never
> initialized because inet6_init() exits before ndisc_init() is called
> which initializes it. Then, if neigh_suppress is enabled and an ICMPv6
> Neighbor Discovery packet reaches the bridge, br_do_suppress_nd() will
> dereference ipv6_stub->nd_tbl which is NULL, passing it to
> neigh_lookup(). This causes a kernel NULL pointer dereference.
> 
>   BUG: kernel NULL pointer dereference, address: 0000000000000268
>   Oops: 0000 [#1] PREEMPT SMP NOPTI
>   [...]
>   RIP: 0010:neigh_lookup+0x16/0xe0
>   [...]
>   Call Trace:
>    <IRQ>
>    ? neigh_lookup+0x16/0xe0
>    br_do_suppress_nd+0x160/0x290 [bridge]
>    br_handle_frame_finish+0x500/0x620 [bridge]
>    br_handle_frame+0x353/0x440 [bridge]
>    __netif_receive_skb_core.constprop.0+0x298/0x1110
>    __netif_receive_skb_one_core+0x3d/0xa0
>    process_backlog+0xa0/0x140
>    __napi_poll+0x2c/0x170
>    net_rx_action+0x2c4/0x3a0
>    handle_softirqs+0xd0/0x270
>    do_softirq+0x3f/0x60
> 
> Fix this by adding a check before br_is_local_ip6() or neigh_lookup()
> call. If ipv6_stub->nd_tbl is NULL, return immediately.
> 
> Fixes: ed842faeb2bd ("bridge: suppress nd pkts on BR_NEIGH_SUPPRESS ports")
> Closes: https://lore.kernel.org/netdev/CAHXs0ORzd62QOG-Fttqa2Cx_A_VFp=utE2H2VTX5nqfgs7LDxQ@mail.gmail.com/
> Signed-off-by: Fernando Fernandez Mancera <[email protected]>
> ---
> Note: I am investigating more places where this might be happening too.
> ---

I can confirm that there is at least one more instance of this problem. 
Although it is not on bridge driver. I will send a patch ASAP.

Thanks,
Fernando.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.