From nobody Mon Sep 07 08:38:09 2026 X-Original-To: dev-commits-src-main@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4hdgSf1tDtz6rh9K for ; Mon, 07 Sep 2026 08:38:10 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "YR2" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4hdgSf0vB4z43QJ for ; Mon, 07 Sep 2026 08:38:10 +0000 (UTC) (envelope-from git@FreeBSD.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788770290; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=xDHtqtW+BwVYUOTjoSCNVS1TY8eRbGum80qk3jSaoZc=; b=FiX5lz9HVz0c8BuNdlHsmp8BXHs9YCWQPNuUHYF288+V0paVo3vIngo29ZT/QXeHDI0crN XQegKL02NufkgtYMu+wiRMcbr4DeKPkbpfSgdBwDCTEmdop4fcZey4NJFR0dkJlEn3XSQX vlcjBjwfSITcWW9AiDDQD13fDHB9JFo2cLS0VUbdLrqB275DUehS43apspq+iQydauA2zm e9oiavsrsqikGF8ry0k1VS05WtWVbezI3N1FWOA9VhSKg2H6U9I3B9XjYiBojvwcw33dVe UTO2IQaTXu3e6iAUHEqYnieZT/TIpPbG2DahG85fS55fqjRZaBhohK19PhNh6g== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1788770290; a=rsa-sha256; cv=none; b=n8vh6nEkugUMZYztiFPUNMYNDsT4HdWwUr5nKzTMKunpMv27t96/fXbroo/G6NEXrG9WGI VEojqaT33+03kKOrT6aWq4v3SRAZIBqVwod3nXuTY9eKVXEU9d7FQfk+n+6jmjM1lGTCGi /VNF6Al2ZBIHXn/TfWeuKWzFKn/LGSfY3fOGjfBFIQzPCmD4d5m9+Xhfx/dpiBl+F7vSoS 3C2DhK7HFQz8GIWy2o3TFJXuvxC2vVmXwt1pQjILI6LL3W/d5/h97AbXHS96uMlLuX2yuy aBzLejCB/v7xjTwq78IvYGJAMKYXWv3YzI5cC/wLh+dnrojabwpv2lPaVkZccw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1788770290; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=xDHtqtW+BwVYUOTjoSCNVS1TY8eRbGum80qk3jSaoZc=; b=GEQqOAhTd5W+Ed3QrtCPgIh13GxEj4DEcVsNqr5SLZ2n0xmbYKCQGT2xm3CpDCAnnBJ8FO VAqy7aQqZf+wBLn9aZWe6woyHUBFxYj1WciIcZG7Uh7EKjWvQKz0HgKL20S8Ixq8FQQDy+ Q1IQLEaPEyMjmHuh1Fak0SC3qKksjBySja6rpaWiKvzeTY2YDW4RXkNXm9uSudjoNWvWzc b5zPczXp+dsUcky4aGecyuR3/WLbfUnJLjICtvfNyC3afVJdYfzfprhqmJYVp0NAIp9+yW LcpHeqzzuDjlt7S5BtQCiTGwfR8NgtHDGSnT6YrF41g7Fp6BVYSxZiiHUe/xDw== Received: from gitrepo.freebsd.org (gitrepo.freebsd.org [IPv6:2610:1c1:1:6068::e6a:5]) by mxrelay.nyi.freebsd.org (Postfix) with ESMTP id 4hdgSd6fc9z18Wn for ; Mon, 07 Sep 2026 08:38:09 +0000 (UTC) (envelope-from git@FreeBSD.org) Received: from git (uid 1279) (envelope-from git@FreeBSD.org) id 3e776 by gitrepo.freebsd.org (DragonFly Mail Agent v0.13+ on gitrepo.freebsd.org); Mon, 07 Sep 2026 08:38:09 +0000 To: src-committers@FreeBSD.org, dev-commits-src-all@FreeBSD.org, dev-commits-src-main@FreeBSD.org From: Kristof Provost Subject: git: 7d810f27c16b - main - pf: Prevent pf dropping TCP state with crafted reset packet. List-Id: Commit messages for the main branch of the src repository List-Archive: https://lists.freebsd.org/archives/dev-commits-src-main List-Help: List-Post: List-Subscribe: List-Unsubscribe: X-BeenThere: dev-commits-src-main@freebsd.org Sender: owner-dev-commits-src-main@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 Content-Type: text/plain; charset=utf-8 Content-Transfer-Encoding: 8bit X-Git-Committer: kp X-Git-Repository: src X-Git-Refname: refs/heads/main X-Git-Reftype: branch X-Git-Commit: 7d810f27c16b1bb151ed701b040febef8f8909fe Auto-Submitted: auto-generated Date: Mon, 07 Sep 2026 08:38:09 +0000 Message-Id: <6a9e77f1.3e776.48158e49@gitrepo.freebsd.org> The branch main has been updated by kp: URL: https://cgit.FreeBSD.org/src/commit/?id=7d810f27c16b1bb151ed701b040febef8f8909fe commit 7d810f27c16b1bb151ed701b040febef8f8909fe Author: Kristof Provost AuthorDate: 2026-09-03 13:57:58 +0000 Commit: Kristof Provost CommitDate: 2026-09-07 08:37:46 +0000 pf: Prevent pf dropping TCP state with crafted reset packet. Revision 1.1212 of pf.c weakened the TCP reset check in stateful connection tracking to let legitimate resets pass in the backwards window. Such a reset is accepted only if its acknowledgment number matches perfectly. But as a workaround for broken stacks, pf replaces an acknowledgment number of 0 in a reset with the tracked sequence of the peer. Then the perfect match always succeeds, and an attacker can spoof resets more easily than intended. Use the acknowledgment number from the wire, before the workaround has modified it. discovered by Minghao Zhang; OK sashan@ Obtained from: OpenBSD, bluhm , 1e0a1f4b82 Sponsored by: Rubicon Communications, LLC ("Netgate") --- sys/netpfil/pf/pf.c | 5 +++-- 1 file changed, 3 insertions(+), 2 deletions(-) diff --git a/sys/netpfil/pf/pf.c b/sys/netpfil/pf/pf.c index 322b10c3fce6..9c9509900ea9 100644 --- a/sys/netpfil/pf/pf.c +++ b/sys/netpfil/pf/pf.c @@ -7290,7 +7290,7 @@ pf_tcp_track_full(struct pf_kstate *state, struct pf_pdesc *pd, { struct tcphdr *th = &pd->hdr.tcp; u_int16_t win = ntohs(th->th_win); - u_int32_t ack, end, data_end, seq, orig_seq; + u_int32_t ack, orig_ack, end, data_end, seq, orig_seq; u_int8_t sws, dws; int ackskew; @@ -7389,6 +7389,7 @@ pf_tcp_track_full(struct pf_kstate *state, struct pf_pdesc *pd, if (tcp_get_flags(th) & TH_FIN) end++; } + orig_ack = ack; if ((tcp_get_flags(th) & TH_ACK) == 0) { /* Let it pass through the ack skew check */ @@ -7442,7 +7443,7 @@ pf_tcp_track_full(struct pf_kstate *state, struct pf_pdesc *pd, (orig_seq == src->seqlo + 1) || (orig_seq + 1 == src->seqlo) || /* Require an exact/+1 sequence match on resets when possible */ (SEQ_GEQ(orig_seq, src->seqlo - (dst->max_win << dws)) && - SEQ_LEQ(orig_seq, src->seqlo + 1) && ackskew == 0 && + SEQ_LEQ(orig_seq, src->seqlo + 1) && orig_ack == dst->seqlo && (th->th_flags & (TH_ACK|TH_RST)) == (TH_ACK|TH_RST)))) { /* Allow resets to match sequence window if ack is perfect match */