git: dc47a6940d60 - main - igmp: Refresh the ip header pointer after m_pullup()

From: Mark Johnston <markj_at_FreeBSD.org>
Date: Tue, 29 Sep 2026 19:23:24 UTC
The branch main has been updated by markj:

URL: https://cgit.FreeBSD.org/src/commit/?id=dc47a6940d60d393b3d36ba0fc5cb84d06fafaea

commit dc47a6940d60d393b3d36ba0fc5cb84d06fafaea
Author:     Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2026-09-29 19:16:57 +0000
Commit:     Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-09-29 19:23:15 +0000

    igmp: Refresh the ip header pointer after m_pullup()
    
    There is a chance that the m_pullup() call immediately above invalidated
    the "ip" pointer, so refresh it as we do with the IGMP header.
    Otherwise the test in igmp_input_v3_query() for whether the packet is an
    IGMPv3 general query might use a pointer to a freed mbuf.
    
    MFC after:      1 week
    Sponsored by:   The FreeBSD Foundation
---
 sys/netinet/igmp.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/sys/netinet/igmp.c b/sys/netinet/igmp.c
index 8c09a37963bd..5c6c46a4f4f2 100644
--- a/sys/netinet/igmp.c
+++ b/sys/netinet/igmp.c
@@ -1605,6 +1605,7 @@ igmp_input(struct mbuf **mp, int *offp, int proto)
 				IGMPSTAT_INC(igps_rcv_tooshort);
 				return (IPPROTO_DONE);
 			}
+			ip = mtod(m, struct ip *);
 			igmpv3 = (struct igmpv3 *)(mtod(m, uint8_t *) + iphlen);
 			if (igmp_input_v3_query(ifp, ip, igmpv3) != 0) {
 				m_freem(m);