Re: [PATCH net-next v2 0/5] bridge: Validate and clean up IPv6 neighbour suppression
| Newsgroups | gmane.linux.network.bridge,gmane.linux.network,gmane.linux.kernel |
|---|---|
| Message-ID | <178614602190.2465504.10010813956529839994.git-patchwork-notify@kernel.org> |
Hello: This series was applied to netdev/net-next.git (main) by Jakub Kicinski <[email protected]>: On Mon, 3 Aug 2026 14:25:00 +0300 you wrote: > The bridge implements IPv6 neighbour suppression by snooping Neighbour > Solicitation and Neighbour Advertisement messages, but it previously only > checked the ICMPv6 type and code before acting on them. This leaves it > open to acting on malformed or spoofed packets that any RFC 4861 compliant > node should reject, and the option parsing in br_nd_send() open-codes a > loop that has historically been a source of bugs. > > [...] Here is the summary with links: - [net-next,v2,1/5] bridge: Use direct pointer in br_is_nd_neigh_msg() https://git.kernel.org/netdev/net-next/c/2cad8e3d9d94 - [net-next,v2,2/5] ipv6: ndisc: Add ndisc_check_ns_na() validation helper https://git.kernel.org/netdev/net-next/c/9dfa6cca8959 - [net-next,v2,3/5] bridge: Validate NS/NA messages using ndisc_check_ns_na() https://git.kernel.org/netdev/net-next/c/18668f4747c9 - [net-next,v2,4/5] bridge: Linearize skb once the ND message type is validated https://git.kernel.org/netdev/net-next/c/67b14d6e36cf - [net-next,v2,5/5] bridge: Use ndisc_parse_options() to parse ND options in br_nd_send() https://git.kernel.org/netdev/net-next/c/7445aaa9fe6d You are awesome, thank you! -- Deet-doot-dot, I am a bot. https://korg.docs.kernel.org/patchwork/pwbot.html