Re: [PATCH net 1/1] ipv6: fix use-after-free in ip6_finish_output2()
Vadim Fedorenko <[email protected]>
| Newsgroups | org.kernel.vger.netdev |
|---|---|
| Message-ID | <[email protected]> |
On 12/08/2026 13:54, Ren Wei wrote: > From: Luxiao Xu <[email protected]> > > ip6_finish_output2() caches a pointer to the IPv6 destination > address (daddr) before invoking lwtunnel_xmit(). The LWT-BPF > transmit path or other encapsulation operations within > lwtunnel_xmit() can reallocate the skb head, freeing the memory > that daddr points to. When lwtunnel_xmit() returns > LWTUNNEL_XMIT_CONTINUE, the function continues to use the stale > daddr pointer to compute the nexthop and to look up or create the > neighbour entry. This results in a use-after-free read, which can > leak sensitive kernel data, pollute the neighbour table with > arbitrary values, misdirect traffic, or crash the system. > > Fix this by re-fetching the IPv6 header and the destination > address pointer after lwtunnel_xmit() returns > LWTUNNEL_XMIT_CONTINUE, ensuring that the subsequent nexthop > computation and neighbour lookup operate on valid memory. > > Fixes: e415ed3a4b8b ("ipv6: use skb_expand_head in ip6_finish_output2") > Cc: [email protected] > Reported-by: Vega <[email protected]> > Assisted-by: Codex:gpt-5.4 > Signed-off-by: Luxiao Xu <[email protected]> > Signed-off-by: Ren Wei <[email protected]> > --- > net/ipv6/ip6_output.c | 2 ++ > 1 file changed, 2 insertions(+) > > diff --git a/net/ipv6/ip6_output.c b/net/ipv6/ip6_output.c > index 368e4fa3b43c..d893c3dacfd6 100644 > --- a/net/ipv6/ip6_output.c > +++ b/net/ipv6/ip6_output.c > @@ -116,6 +116,8 @@ static int ip6_finish_output2(struct net *net, struct sock *sk, struct sk_buff * > > if (res != LWTUNNEL_XMIT_CONTINUE) > return res; > + hdr = ipv6_hdr(skb); > + daddr = &hdr->daddr; > } > > IP6_UPD_PO_STATS(net, idev, IPSTATS_MIB_OUT, skb->len); Reviewed-by: Vadim Fedorenko <[email protected]>