Re: [PATCH 1/2] net: dhcp6: prevent an infinite loop parsing IA options

Jerome Forissier <[email protected]>
Newsgroups org.u-boot-project.lists.u-boot
Message-ID <[email protected]>

On 07/08/2026 16:52, Shahriyar Jalayeri wrote:
> dhcp6_parse_ia_options() walks the sub-options encapsulated in a received
> IA_NA / IA_TA option and advances its cursor by the sub-option's declared
> length alone. A sub-option with a length of zero never advances the
> cursor, so the while loop spins forever and the DHCPv6 client hangs. The
> advance also omits the sub-option header, so it is short even for
> well-formed options.
> 
> An attacker on the local link able to answer the client's SOLICIT during
> a netboot can send an ADVERTISE whose IA_NA carries a zero-length
> encapsulated sub-option and hang the client; the IA_ID it has to match is
> observable in the client's SOLICIT.
> 
> Advance the cursor by the sub-option header size plus its length so every
> iteration makes forward progress and the walk matches the option layout.
> 
> Fixes: a0245818f7f8 ("net: dhcp6: Add DHCPv6 (DHCP for IPv6)")
> Signed-off-by: Shahriyar Jalayeri <[email protected]>
> ---
>  net/dhcpv6.c | 3 ++-
>  1 file changed, 2 insertions(+), 1 deletion(-)
> 
> diff --git a/net/dhcpv6.c b/net/dhcpv6.c
> index 640f089a2e1..1e92d744615 100644
> --- a/net/dhcpv6.c
> +++ b/net/dhcpv6.c
> @@ -285,7 +285,8 @@ static void dhcp6_parse_ia_options(struct dhcp6_option_hdr *ia_ptr, uchar *ia_op
>  			break;
>  		}
>  
> -		ia_option_ptr += ntohs(((struct dhcp6_option_hdr *)ia_option_ptr)->option_len);
> +		ia_option_ptr += sizeof(struct dhcp6_option_hdr) +
> +				 ntohs(((struct dhcp6_option_hdr *)ia_option_ptr)->option_len);
>  	}
>  }

This fixes the lack of forward progress, but the nested-option walk still has
two issues:

First, ia_option_hdr is initialized before the loop and never updated after
ia_option_ptr advances, so every subsequent sub-option is interpreted using
the first sub-option’s ID.

Also, the code does not verify that each sub-option header and its declared
payload fit within the enclosing IA option, which may permit out-of-bounds
reads.

Could you address these issues in v2?

Thanks,
-- 
Jerome
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.