git: dc47a6940d60 - main - igmp: Refresh the ip header pointer after m_pullup()
- Go to: [ bottom of page ] [ top of archives ] [ this month ]
Date: Tue, 29 Sep 2026 19:23:24 UTC
The branch main has been updated by markj:
URL: https://cgit.FreeBSD.org/src/commit/?id=dc47a6940d60d393b3d36ba0fc5cb84d06fafaea
commit dc47a6940d60d393b3d36ba0fc5cb84d06fafaea
Author: Mark Johnston <markj@FreeBSD.org>
AuthorDate: 2026-09-29 19:16:57 +0000
Commit: Mark Johnston <markj@FreeBSD.org>
CommitDate: 2026-09-29 19:23:15 +0000
igmp: Refresh the ip header pointer after m_pullup()
There is a chance that the m_pullup() call immediately above invalidated
the "ip" pointer, so refresh it as we do with the IGMP header.
Otherwise the test in igmp_input_v3_query() for whether the packet is an
IGMPv3 general query might use a pointer to a freed mbuf.
MFC after: 1 week
Sponsored by: The FreeBSD Foundation
---
sys/netinet/igmp.c | 1 +
1 file changed, 1 insertion(+)
diff --git a/sys/netinet/igmp.c b/sys/netinet/igmp.c
index 8c09a37963bd..5c6c46a4f4f2 100644
--- a/sys/netinet/igmp.c
+++ b/sys/netinet/igmp.c
@@ -1605,6 +1605,7 @@ igmp_input(struct mbuf **mp, int *offp, int proto)
IGMPSTAT_INC(igps_rcv_tooshort);
return (IPPROTO_DONE);
}
+ ip = mtod(m, struct ip *);
igmpv3 = (struct igmpv3 *)(mtod(m, uint8_t *) + iphlen);
if (igmp_input_v3_query(ifp, ip, igmpv3) != 0) {
m_freem(m);