From nobody Mon May 11 13:33:36 2026 X-Original-To: bugs@mlmmj.nyi.freebsd.org Received: from mx1.freebsd.org (mx1.freebsd.org [IPv6:2610:1c1:1:606c::19:1]) by mlmmj.nyi.freebsd.org (Postfix) with ESMTP id 4gDgfS5ZWKz6d2Rs for ; Mon, 11 May 2026 13:33:36 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from mxrelay.nyi.freebsd.org (mxrelay.nyi.freebsd.org [IPv6:2610:1c1:1:606c::19:3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256 client-signature RSA-PSS (4096 bits) client-digest SHA256) (Client CN "mxrelay.nyi.freebsd.org", Issuer "R13" (not verified)) by mx1.freebsd.org (Postfix) with ESMTPS id 4gDgfS537Bz3jMw for ; Mon, 11 May 2026 13:33:36 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1778506416; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=gF75+8wj69Rio8ypDv3HN1GIV3bIq2ONDpY4h0XjztE=; b=kdxl4ORhaetIakdVvelZABziKuHkG0NOad0T1/T1D36rQ9skO3Brkag1N2/UQfY+2utDK1 B3QU5eYJnIM3f7pujmMV/xXtbokkqWWV2uQfLH71dmEk4TF/492rxxHDckjz9HHJt11qux HAVnYuH1BZSaq/KfgRHR875uakUHU0JhQ709fCa8un8pOleBAl2yl0MJjXnz4H8usHbm/f 0CqXKBMEv9q6/Cc4XNykaaZadIae80hh+zD/nQdeO9MtPsscvJHuBrRC/3ugbNLKLSecKk /UHFoF3nWN5vHmhnuyY3NV4LvEMmdcOTQ5/sJICRgZfzmTH+AKTmX9K2HTWbiA== ARC-Seal: i=1; s=dkim; d=freebsd.org; t=1778506416; a=rsa-sha256; cv=none; b=U9K2vdo3rv1XzakMHQBf9sLx6diccW8OxYRnIIOQuhFRJgH1X9tAgD1GzAAHDZg2ClXrCr LXIyZWjzUeHW2S1aJ6KNmy3piNcng5BvX05HRamFSuAjifSNa4/dGXAfg3q88yX7tTdD+T 3aqSxV71H8d3tTb1VtbYAranjTJLvgdLpCaf4Ze88ANq2ZnaouVUDLOWpkaP+h98BqEvKa mESyCOtqADcgBWJxutnXLNc/3TMXVqpepKa0JacCi1dG+/jeN5D35WJrNXOui+CMd/koIX p1FeS6fmmblU0i459y40dT5K00wd1AL/geO6nfzYMtpZeGRVGyNHIHucTPrMaw== ARC-Authentication-Results: i=1; mx1.freebsd.org; none ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=freebsd.org; s=dkim; t=1778506416; h=from:from:reply-to:subject:subject:date:date:message-id:message-id: to:to:cc:mime-version:mime-version:content-type:content-type: content-transfer-encoding:content-transfer-encoding; bh=gF75+8wj69Rio8ypDv3HN1GIV3bIq2ONDpY4h0XjztE=; b=MJLfUviGigFgpma45b/aASiKP8MGctXZtApLv4t+4Yd0IHkKMLjD2wQp+y6uXl97iyb3bw rnuLHNfB9Y3eZCRObzAJSwRwHP0Ssd2S1q2k9j+QDfYd3DNNyhY4WpAUYpsK8haRIIO5DT MMu9Wfi6mtBHbFPh/ucB/dmBzvSpjjA1KQ1znpJbvORGZ5KnvnYl2BsbHbV3PwxHbGjo8U Jj79J6FWERcvxdePF177922u8LzFiZR3AncL/1RcdIeLjAL5oooS3IrRT25UJUEM7hfk65 y/vnzMf8kHiIjEH/0jCYX+2nUXsRNqaWgjXf1LkmeoXd+DwBgX28jqbwK6TLtA== Received: from kenobi.freebsd.org (kenobi.freebsd.org [IPv6:2610:1c1:1:606c::50:1d]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (Client did not present a certificate) by mxrelay.nyi.freebsd.org (Postfix) with ESMTPS id 4gDgfS4RfDz3bh for ; Mon, 11 May 2026 13:33:36 +0000 (UTC) (envelope-from bugzilla-noreply@freebsd.org) Received: from kenobi.freebsd.org ([127.0.1.5]) by kenobi.freebsd.org (8.15.2/8.15.2) with ESMTP id 64BDXamA069633 for ; Mon, 11 May 2026 13:33:36 GMT (envelope-from bugzilla-noreply@freebsd.org) Received: (from www@localhost) by kenobi.freebsd.org (8.15.2/8.15.2/Submit) id 64BDXaAR069632 for bugs@FreeBSD.org; Mon, 11 May 2026 13:33:36 GMT (envelope-from bugzilla-noreply@freebsd.org) X-Authentication-Warning: kenobi.freebsd.org: www set sender to bugzilla-noreply@freebsd.org using -f From: bugzilla-noreply@freebsd.org To: bugs@FreeBSD.org Subject: [Bug 295198] ipfilter apparently doesn't validate packet lengths Date: Mon, 11 May 2026 13:33:36 +0000 X-Bugzilla-Reason: AssignedTo X-Bugzilla-Type: new X-Bugzilla-Watch-Reason: None X-Bugzilla-Product: Base System X-Bugzilla-Component: kern X-Bugzilla-Version: CURRENT X-Bugzilla-Keywords: X-Bugzilla-Severity: Affects Only Me X-Bugzilla-Who: markj@FreeBSD.org X-Bugzilla-Status: New X-Bugzilla-Resolution: X-Bugzilla-Priority: --- X-Bugzilla-Assigned-To: bugs@FreeBSD.org X-Bugzilla-Flags: X-Bugzilla-Changed-Fields: bug_id short_desc product version rep_platform op_sys bug_status bug_severity priority component assigned_to reporter Message-ID: Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="UTF-8" X-Bugzilla-URL: https://bugs.freebsd.org/bugzilla/ Auto-Submitted: auto-generated List-Id: Bug reports List-Archive: https://lists.freebsd.org/archives/freebsd-bugs List-Help: List-Post: List-Subscribe: List-Unsubscribe: Sender: owner-freebsd-bugs@FreeBSD.org List-Id: List-Post: List-Help: List-Subscribe: List-Unsubscribe: List-Owner: Precedence: list MIME-Version: 1.0 https://bugs.freebsd.org/bugzilla/show_bug.cgi?id=3D295198 Bug ID: 295198 Summary: ipfilter apparently doesn't validate packet lengths Product: Base System Version: CURRENT Hardware: Any OS: Any Status: New Severity: Affects Only Me Priority: --- Component: kern Assignee: bugs@FreeBSD.org Reporter: markj@FreeBSD.org I saw a crash while running the test suite: panic: in6_cksum_partial_l2: mbuf len (51) < off(40)+len(512)=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20 cpuid =3D 8=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20 time =3D 1778434309=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20 KDB: stack backtrace:=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20 db_trace_self_wrapper() at db_trace_self_wrapper+0xa5/frame 0xfffffe00f11d7= c70=20=20 kdb_backtrace() at kdb_backtrace+0xc6/frame 0xfffffe00f11d7dd0=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20 vpanic() at vpanic+0x214/frame 0xfffffe00f11d7f70=20=20=20=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20 panic() at panic+0xb5/frame 0xfffffe00f11d8030=20=20=20=20=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20 in6_cksum_partial_l2() at in6_cksum_partial_l2+0x37e/frame 0xfffffe00f11d81= 20=20=20=20 fr_cksum() at fr_cksum+0x155/frame 0xfffffe00f11d8180=20=20=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20 ipf_checkl4sum() at ipf_checkl4sum+0x144/frame 0xfffffe00f11d81c0=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20 ipf_checkv6sum() at ipf_checkv6sum+0x81/frame 0xfffffe00f11d81f0=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20 ipf_makefrip() at ipf_makefrip+0x2396/frame 0xfffffe00f11d8350=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20 ipf_check() at ipf_check+0x3c4/frame 0xfffffe00f11d85f0=20=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20 ipf_check_wrapper6() at ipf_check_wrapper6+0xd3/frame 0xfffffe00f11d8650=20= =20=20=20=20=20=20=20 pfil_mbuf_in() at pfil_mbuf_in+0x7c/frame 0xfffffe00f11d8690=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20 ip6_input() at ip6_input+0xbdd/frame 0xfffffe00f11d88b0=20=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20 netisr_dispatch_src() at netisr_dispatch_src+0x1aa/frame 0xfffffe00f11d8990= =20=20=20=20=20 ether_demux() at ether_demux+0x301/frame 0xfffffe00f11d8a50=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20 ether_nh_input() at ether_nh_input+0x6ec/frame 0xfffffe00f11d8b30=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20 netisr_dispatch_src() at netisr_dispatch_src+0x1aa/frame 0xfffffe00f11d8c10= =20=20=20=20=20 ether_input() at ether_input+0x1ac/frame 0xfffffe00f11d8cf0=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20 epair_tx_start_deferred() at epair_tx_start_deferred+0x140/frame 0xfffffe00f11d8d50=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20 taskqueue_run_locked() at taskqueue_run_locked+0x3c2/frame 0xfffffe00f11d8e= b0=20=20=20 taskqueue_thread_loop() at taskqueue_thread_loop+0x138/frame 0xfffffe00f11d= 8ef0=20 fork_exit() at fork_exit+0xa3/frame 0xfffffe00f11d8f30=20=20=20=20=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20=20 fork_trampoline() at fork_trampoline+0xe/frame 0xfffffe00f11d8f30=20=20=20= =20=20=20=20=20=20=20=20=20=20=20=20 --- trap 0x5be18f56, rip =3D 0x10b55be18f96, rsp =3D 0x10b55be18fc6, rbp =3D 0x10b55be18ee6 --- The basic problem here is: (gdb) frame 25 #25 ipf_makefrip (hlen=3Dhlen@entry=3D40, ip=3Dip@entry=3D0xfffffe00f40c456= e, fin=3Dfin@entry=3D0xfffffe00f11d8410) at /home/markj/sb/main/src/sys/netpfil/ipfilter/netinet/fil.c:2029 2029 ipf_pr_ipv6hdr(fin); (gdb) p fin->fin_plen=20 $17 =3D 552 (gdb) p fin->fin_m->m_pkthdr.len $18 =3D 51 That is, the packet's IPv6 header says the packet is longer than it actually is. This causes an underflow in fr_cksum() which causes the panic.=20 Surprisingly I cannot find any code in ipfilter which actually checks for t= his condition. Of course, ip6_input() does, but that happens after pfil hooks = run. So I presume we should add a check for this, presumably in ipf_makefrip(), after the protocol-specific packet length field is extracted. But who knows what other validation is missing. --=20 You are receiving this mail because: You are the assignee for the bug.=