From mboxrd@z Thu Jan 1 00:00:00 1970 Authentication-Results: mail.toke.dk; dkim=pass header.d=gmail.com header.i=@gmail.com header.a=rsa-sha256 header.s=20251104 header.b="JG40eV/S"; arc=none (Message is not ARC signed); dmarc=pass (Used From Domain Record) header.from=gmail.com policy.dmarc=quarantine Received: from mail-pg1-x536.google.com (mail-pg1-x536.google.com [IPv6:2607:f8b0:4864:20::536]) by mail.toke.dk (Postfix) with ESMTPS id A5DA113CAFD4 for ; Mon, 27 Jul 2026 19:03:55 +0200 (CEST) Received: by mail-pg1-x536.google.com with SMTP id 41be03b00d2f7-c9b373d5af0so2147893a12.2 for ; Mon, 27 Jul 2026 10:03:55 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785171834; x=1785776634; darn=lists.bufferbloat.net; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to:content-type; bh=1FQqBAZFhP/Xf7sj1hAmF9i/PIJNITF2uATGYHmJRQU=; b=JG40eV/SdWw2v+xbERm02GRCF1bX6UVkDveiTH8EEGgoSXksMyN0HvE1ArCHUXsc3y 9VABTgr3rnyCaywGod4wk9Z+tj46e48jqu0YfUNV2+LVSWEqmV56sq+3K9K81RlncswY yLmsJlYgZ+oSmhDgAIsBvr1hkY9R96n3FbJl77vaNQ4+0gSDHW6BQBkv4nbeC8Kxycdv IcH8m+AVl4Ru1Z6r3XGk9bB5GLhQ2/vhZnomaS133uea/Xz+FMI8hZ/HlDuqsx73kJRA ZlE4T3zPEzjgY5hxJcRGT6Tl7H/0uOuNP0sCxvT0xOK900DAHTwRkCEwb2SDImSXBk1l vLYQ== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785171834; x=1785776634; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to:content-type; bh=1FQqBAZFhP/Xf7sj1hAmF9i/PIJNITF2uATGYHmJRQU=; b=Pt3n7rzwDvWosHHfqYFRLD//sUf3hNsNGSTBNJgemvB9+L1ysIOsclRy1ZeyTeKOpx BA4dg283KXnZEtSSdM/J9g0SgFQdft4jNZCBzXLDVPTgwx2iu+mZezs0tCE3Bm0N5/7v gWSS++HWL2JDQff1Zh2KpbdWBlO0N1QjvLRcSlPt9oriFvIKEYICjr6LZrDOz/bJAL2D qV4TuwmNnKuEa+WSFqfzFrNHJ7pNDT6scB72hHNDfs+O0tg19xKhNB5x4U0cnQKZZm8g ssx4bHU3ltr1QBEmHXyFprs21qlf3OS/WNqgLuqFToJn5PzxI+G8hjR7WCiMVHQ3VZRR lQ8g== X-Gm-Message-State: AOJu0YxRNdGJjT3fK5CkZm5HR7dpqN3xIL5KU7ZLvC9BjWJnkXq9CYv6 3PHskx0zuyw4dxsdLpXzYRX+t6HXa0A219IGqqMECMs+BKflWcFSPgsyOXbtHBUygJQ= X-Gm-Gg: AR+sD124dMFFgqv99MiNJPrpG0bBwwT7h2SCXBuvJ/Il0HOx+O62igBRbNXNX81MsIX CRyJeKOm8LfkcthUzkAoKstdiGF8CxbanBvNxYlx2vRdE505OdyV25kmWWgj8DNaS6T6/8tKq/r q1mDgjvEUrMkc+idn66iareQcD0tOo5yyBxQtmWgRM1gwDDoyUf6a+PidvBg0N+07ea/A/iGPcH RdM4qp2k/+PXCU3mJ5Kg68w3oIQipYfjxkZEmhKtQ14NzfpqOgNEzxRfMJf8l2T3Q7u9sgKePge ut+eOYnbwC8VWSvZER1Z1DB3UAPWNZkCH2EoD9UbZXzG4LSMj8IOhvYu6SmYDJOvD1vBixElUDr 6DRRe9De074DbZFYIGNnMO26sQH382JKwEFMJ2TVUaEJrkscoXju4mKBSD+TITzulJE5g/g8+mc sns36T4YGNIUwydcYYYhEaJ4pxT1pDmsQ= X-Received: by 2002:a05:6a20:b598:b0:3b1:cce5:9140 with SMTP id adf61e73a8af0-3c67dab6bafmr9142111637.33.1785171833721; Mon, 27 Jul 2026 10:03:53 -0700 (PDT) Received: from enjou-Legion-Y7000P-2019 ([219.141.235.82]) by smtp.gmail.com with ESMTPSA id 41be03b00d2f7-cbbb66e0ccdsm3546131a12.32.2026.07.27.10.03.50 (version=TLS1_3 cipher=TLS_AES_256_GCM_SHA384 bits=256/256); Mon, 27 Jul 2026 10:03:53 -0700 (PDT) From: Ren Wei To: cake@lists.bufferbloat.net, netdev@vger.kernel.org Cc: toke@toke.dk, jhs@mojatatu.com, jiri@resnulli.us, davem@davemloft.net, edumazet@google.com, pabeni@redhat.com, horms@kernel.org, vega@nebusec.ai, zhilinz@nebusec.ai, enjou1224z@gmail.com Date: Tue, 28 Jul 2026 01:03:41 +0800 Message-ID: <502a543e7f04d14a15a0f6cecab30dbdf77033d1.1784855599.git.zhilinz@nebusec.ai> X-Mailer: git-send-email 2.51.0 In-Reply-To: References: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-MailFrom: enjou1224z@gmail.com X-Mailman-Rule-Hits: nonmember-moderation X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; loop; banned-address; emergency; member-moderation Message-ID-Hash: V45QISH3URTF2N7PESIBHRUMUMM3ROQ4 X-Message-ID-Hash: V45QISH3URTF2N7PESIBHRUMUMM3ROQ4 X-Mailman-Approved-At: Tue, 28 Jul 2026 10:39:56 +0200 X-Mailman-Version: 3.3.10 Precedence: list Subject: [Cake] [PATCH net 1/1] net/sched: sch_cake: validate 6in4 inner headers List-Id: Cake - FQ_codel the next generation Archived-At: List-Archive: List-Help: List-Owner: List-Post: List-Subscribe: List-Unsubscribe: From: Zhiling Zou CAKE's ACK filter special-cases IPv4 packets carrying IPv6 to find TCP ACKs inside 6in4 tunnels. The parser checks the outer IPv4 protocol and the inner next-header field, but it does not verify that the inner header is actually IPv6. A malformed packet can therefore use an inner header with a non-IPv6 version while still setting the byte used as nexthdr to TCP. When two packets from the same queued flow reach cake_ack_filter(), the version dispatch can fall through to WARN_ON(1), which becomes a denial of service on kernels with panic_on_warn enabled. Reject 6in4 packets unless the encapsulated header has IPv6 version 6 in both IP and TCP header parsing helpers. Fixes: 8b7138814f29 ("sch_cake: Add optional ACK filter") Cc: stable@vger.kernel.org Reported-by: Vega Assisted-by: Codex:gpt-5.4 Signed-off-by: Zhiling Zou Signed-off-by: Ren Wei --- net/sched/sch_cake.c | 18 +++++++++++------- 1 file changed, 11 insertions(+), 7 deletions(-) diff --git a/net/sched/sch_cake.c b/net/sched/sch_cake.c index 505f63fecf640..7c4d92cdf514f 100644 --- a/net/sched/sch_cake.c +++ b/net/sched/sch_cake.c @@ -950,16 +950,19 @@ static struct iphdr *cake_get_iphdr(const struct sk_buff *skb, if (!iph) return NULL; - if (iph->version == 4 && iph->protocol == IPPROTO_IPV6) - return skb_header_pointer(skb, offset + iph->ihl * 4, - sizeof(struct ipv6hdr), buf); + if (iph->version == 4 && iph->protocol == IPPROTO_IPV6) { + iph = skb_header_pointer(skb, offset + iph->ihl * 4, + sizeof(struct ipv6hdr), buf); + if (!iph || iph->version != 6) + return NULL; - else if (iph->version == 4) return iph; - - else if (iph->version == 6) + } else if (iph->version == 4) { + return iph; + } else if (iph->version == 6) { return skb_header_pointer(skb, offset, sizeof(struct ipv6hdr), buf); + } return NULL; } @@ -990,7 +993,8 @@ static struct tcphdr *cake_get_tcphdr(const struct sk_buff *skb, ipv6h = skb_header_pointer(skb, offset, sizeof(_ipv6h), &_ipv6h); - if (!ipv6h || ipv6h->nexthdr != IPPROTO_TCP) + if (!ipv6h || ipv6h->version != 6 || + ipv6h->nexthdr != IPPROTO_TCP) return NULL; offset += sizeof(struct ipv6hdr); -- 2.43.0