Re: [PATCH net 3/3] vxlan: validate ND option lengths in vxlan_na_create
Nikolay Aleksandrov <[email protected]>
| Newsgroups | gmane.linux.network.bridge,gmane.linux.network,gmane.linux.kernel |
|---|---|
| Message-ID | <[email protected]> |
On 26/03/2026 05:44, Yang Yang wrote:
> vxlan_na_create() walks ND options according to option-provided
> lengths. A malformed option can make the parser advance beyond the
> computed option span or use a too-short source LLADDR option payload.
>
> Validate option lengths against the remaining NS option area before
> advancing, and only read source LLADDR when the option is large enough
> for an Ethernet address.
>
> Fixes: 4b29dba9c085 ("vxlan: fix nonfunctional neigh_reduce()")
> Cc: [email protected]
> Reported-by: Yifan Wu <[email protected]>
> Reported-by: Juefei Pu <[email protected]>
> Tested-by: Ao Zhou <[email protected]>
> Co-developed-by: Yuan Tan <[email protected]>
> Signed-off-by: Yuan Tan <[email protected]>
> Suggested-by: Xin Liu <[email protected]>
> Signed-off-by: Yang Yang <[email protected]>
> ---
> drivers/net/vxlan/vxlan_core.c | 6 ++++--
> 1 file changed, 4 insertions(+), 2 deletions(-)
>
> diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c
> index 17c941aac32db..a94ac82a61364 100644
> --- a/drivers/net/vxlan/vxlan_core.c
> +++ b/drivers/net/vxlan/vxlan_core.c
> @@ -1965,12 +1965,14 @@ static struct sk_buff *vxlan_na_create(struct sk_buff *request,
> ns_olen = request->len - skb_network_offset(request) -
> sizeof(struct ipv6hdr) - sizeof(*ns);
> for (i = 0; i < ns_olen-1; i += (ns->opt[i+1]<<3)) {
> - if (!ns->opt[i + 1]) {
> + if (!ns->opt[i + 1] || i + (ns->opt[i + 1] << 3) > ns_olen) {
> kfree_skb(reply);
> return NULL;
> }
> if (ns->opt[i] == ND_OPT_SOURCE_LL_ADDR) {
> - daddr = ns->opt + i + sizeof(struct nd_opt_hdr);
> + if ((ns->opt[i + 1] << 3) >=
> + sizeof(struct nd_opt_hdr) + ETH_ALEN)
> + daddr = ns->opt + i + sizeof(struct nd_opt_hdr);
> break;
> }
> }
Acked-by: Nikolay Aleksandrov <[email protected]>