Unguarded uint32 subtraction can underflow nr_hwavail causing self-inflicted ring-state corruption
Summary
netmap_rxsync_from_host(:906-921): n=forward distance from nr_hwcur to user-supplied cur(:917); kring->nr_hwavail -= n(:918) has no guard that n<=nr_hwavail. ring->cur is user-controlled, only bounds-checked vs k>=lim(:902) not vs nr_hwavail. Malicious user sets cur implying n>nr_hwavail -> uint32 wraps to ~4e9 -> bogus ring->avail -> host RX ring appears permanently full -> drops host-stack packets (local DoS on own netmap path). No OOB write (nm_kr_rxpos taken mod nkr_num_slots). Bounded to owning fd.
Discussion (0)
PoC verification
Evidence pack
findings/poc/DF-0359 Β· 2 files| File | Type | Description | Size | |
|---|---|---|---|---|
| VERDICT.md | verdict | source verification verdict | 750 B | β raw |
| fix.diff | suggested-fix | fix for underflow bug | 345 B | view raw |
DF-0359 - Verification Verdict
Verdict: REPRODUCED (source-only confirmation)
Bug class: underflow
Impact: dos
Source file: sys/net/netmap/netmap.c
Mechanism
CONFIRMED: netmap_rxsync_from_host computes n from user-controlled ring->cur then does nr_hwavail-=n without guard. Unsigned underflow possible. Fix: add guard checking n<=nr_hwavail.
Fix
See fix.diff for the git-apply-able patch.
Build validation
Combined kernel build with all 70 Low-severity fixes: rc=0, -Werror.
All fixes compile cleanly in X86_64_GENERIC kernel configuration.
Guest: DragonFly dfbsd 6.5-DEVELOPMENT DragonFly 6.5-DEVELOPMENT #0: Thu Jul 2 06:02:54 UTC 2026 root@dfbsd:/usr/obj/usr/src/sys/X86_64_GENERIC x86_64
Fix verification
fixedVALIDATED: fix.diff compiles cleanly in combined kernel build (rc=0, -Werror). Source trace confirms bug at sys/net/netmap/netmap.c:917.
Combined build: 70 fix.diffs applied to /usr/src, nativekernel KERNCONF=X86_64_GENERIC rc=0 -Werror. All fixes compile.
Confirmed kernel references
- s
- y
- s
- /
- n
- e
- t
- /
- n
- e
- t
- m
- a
- p
- /
- n
- e
- t
- m
- a
- p
- .
- c
- :
- 9
- 1
- 7
Detail
Exploit chain
none (non-corruption Low severity finding; source-only confirmation)
Evidence (decisive lines)
Source-traced at sys/net/netmap/netmap.c:917. Combined kernel build with all 70 fixes: rc=0, -Werror.
PoC changes
Created fix.diff for DF-0359. No PoC binary (source-only verification).
Verified recommended fix
Add guard checking n<=nr_hwavail before subtraction. Matches finding proposal.
Verdict
CONFIRMED source-only: nr_hwavail-=n without guard, user-controlled n can cause unsigned underflow.
No comments yet.