Re: [BUG] net/bridge: out-of-bounds in br_forward()

Nikolay Aleksandrov <[email protected]>
Newsgroups gmane.linux.network.bridge
Message-ID <ddf53430-f3ce-4ca8-aacd-3fd8ffc81091__28490.7136739761$1787841376$gmane$org@blackwall.org>
On 27/08/2026 17:29, Florian Westphal wrote:
> co <[email protected]> wrote:
>> We found a bug reachable in:
>>
>>      path    net/bridge/netfilter
>>      crash   out-of-bounds in br_forward()
>>      commit  7b5344954050 ("Merge tag 'nf-26-08-10' of git://git.kernel.org/pub/scm/linux/kernel/git/netfilter/nf")
> 
> I'm looking into these reports, I think this is the same
> underlying bug as the other report; a variant of
> 
> ccb9fd4b8753 ("netfilter: revalidate bridge ports")
> 
> That bug uses nfnetlink_queue for RCU escape, the other two reports
> use defrag engine.
> 
> And sure, its br_netfilter again -- I think we will have to consider
> removing it even though it will break existing setups.
> 

+10

> As a compromise, I suggest to reject br_netfilter in user namespaces,
> i.e. call_iptables cannot be enabled anymore unless you have
> CAP_NET_ADMIN in init net.

+1000 :)

I absolutely agree on both counts.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.