Re: [PATCH 1/2 net v3] net: bridge: fix nd_tbl NULL dereference when IPv6 is disabled

Nikolay Aleksandrov <[email protected]>
Newsgroups gmane.linux.network.bridge,gmane.linux.network
Message-ID <aamFRR3rfa1TlHEF@penguin>
On Wed, Mar 04, 2026 at 01:03:56PM +0100, Fernando Fernandez Mancera wrote:
> When booting with the 'ipv6.disable=1' parameter, the nd_tbl is never
> initialized because inet6_init() exits before ndisc_init() is called
> which initializes it. Then, if neigh_suppress is enabled and an ICMPv6
> Neighbor Discovery packet reaches the bridge, br_do_suppress_nd() will
> dereference ipv6_stub->nd_tbl which is NULL, passing it to
> neigh_lookup(). This causes a kernel NULL pointer dereference.
> 
>  BUG: kernel NULL pointer dereference, address: 0000000000000268
>  Oops: 0000 [#1] PREEMPT SMP NOPTI
>  [...]
>  RIP: 0010:neigh_lookup+0x16/0xe0
>  [...]
>  Call Trace:
>   <IRQ>
>   ? neigh_lookup+0x16/0xe0
>   br_do_suppress_nd+0x160/0x290 [bridge]
>   br_handle_frame_finish+0x500/0x620 [bridge]
>   br_handle_frame+0x353/0x440 [bridge]
>   __netif_receive_skb_core.constprop.0+0x298/0x1110
>   __netif_receive_skb_one_core+0x3d/0xa0
>   process_backlog+0xa0/0x140
>   __napi_poll+0x2c/0x170
>   net_rx_action+0x2c4/0x3a0
>   handle_softirqs+0xd0/0x270
>   do_softirq+0x3f/0x60
> 
> Fix this by replacing IS_ENABLED(IPV6) call with ipv6_mod_enabled() in
> the callers. This is in essence disabling NS/NA suppression when IPv6 is
> disabled.
> 
> Fixes: ed842faeb2bd ("bridge: suppress nd pkts on BR_NEIGH_SUPPRESS ports")
> Reported-by: Guruprasad C P <[email protected]>
> Closes: https://lore.kernel.org/netdev/CAHXs0ORzd62QOG-Fttqa2Cx_A_VFp=utE2H2VTX5nqfgs7LDxQ@mail.gmail.com/
> Signed-off-by: Fernando Fernandez Mancera <[email protected]>
> ---
> v2: use ipv6_mod_enabled() instead of a null check and replace the check
> on the caller
> v3: no changes
> ---

Acked-by: Nikolay Aleksandrov <[email protected]>
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.