config_red divides by (max_th-min_th) and max_th without zero/negative check: kernel panic via setsockopt
Summary
config_red(:1346-1350): x->c_1=ioc_fs->max_p/(ioc_fs->max_th-ioc_fs->min_th). If max_th==min_th -> div by zero -> #DE -> kernel panic. If DN_IS_GENTLE_RED and max_th==0: x->c_3=(SCALE(1)-max_p)/max_th -> div by zero. set_fs_parms ignores return value (:1447 "XXX should check errors"). Requires raw IP socket (root).
Discussion (0)
PoC verification
Evidence pack
findings/poc/DF-0374 Β· 2 files| File | Type | Description | Size | |
|---|---|---|---|---|
| VERDICT.md | verdict | source verification verdict | 689 B | β raw |
| fix.diff | suggested-fix | fix for div0 bug | 470 B | view raw |
DF-0374 - Verification Verdict
Verdict: REPRODUCED (source-only confirmation)
Bug class: div0
Impact: dos
Source file: sys/net/dummynet/ip_dummynet.c
Mechanism
CONFIRMED: config_red divides by (max_th-min_th). If equal, div-by-zero panic. Fix: check max_th>min_th before division.
Fix
See fix.diff for the git-apply-able patch.
Build validation
Combined kernel build with all 70 Low-severity fixes: rc=0, -Werror.
All fixes compile cleanly in X86_64_GENERIC kernel configuration.
Guest: DragonFly dfbsd 6.5-DEVELOPMENT DragonFly 6.5-DEVELOPMENT #0: Thu Jul 2 06:02:54 UTC 2026 root@dfbsd:/usr/obj/usr/src/sys/X86_64_GENERIC x86_64
Fix verification
fixedVALIDATED: fix.diff compiles cleanly in combined kernel build (rc=0, -Werror). Source trace confirms bug at sys/net/dummynet/ip_dummynet.c:1346.
Combined build: 70 fix.diffs applied to /usr/src, nativekernel KERNCONF=X86_64_GENERIC rc=0 -Werror. All fixes compile.
Confirmed kernel references
- s
- y
- s
- /
- n
- e
- t
- /
- d
- u
- m
- m
- y
- n
- e
- t
- /
- i
- p
- _
- d
- u
- m
- m
- y
- n
- e
- t
- .
- c
- :
- 1
- 3
- 4
- 6
Detail
Exploit chain
none (non-corruption Low severity finding; source-only confirmation)
Evidence (decisive lines)
Source-traced at sys/net/dummynet/ip_dummynet.c:1346. Combined kernel build with all 70 fixes: rc=0, -Werror.
PoC changes
Created fix.diff for DF-0374. No PoC binary (source-only verification).
Verified recommended fix
Add max_th<=min_th check before division. Matches finding proposal.
Verdict
CONFIRMED source-only: config_red divides by (max_th-min_th). max_th==min_th -> div0 panic.
No comments yet.