bpf_movein IEEE80211_RADIO path: ibp_len from user packet drives link-header copy without proper mbuf bounds check
Summary
bpf_movein DLT_IEEE80211_RADIO(:264-274): hlen=p->ibp_len from user packet, only bounded vs sizeof(sa_data)(:266) not vs m->m_len. bcopy(m_data,sa_data,hlen)(:271) + m_data+=hlen/m_len-=hlen(:272-274). If sizeof(ieee80211_bpf_params) < sizeof(sa_data) in future -> ibp_len in gap causes OOB read past supplied data + m_len underflow. Currently safe by accident (sizeof struct >= sizeof sa_data). Fragile, defense-in-depth.
Discussion (0)
PoC verification
Evidence pack
findings/poc/DF-0435 Β· 2 files| File | Type | Description | Size | |
|---|---|---|---|---|
| VERDICT.md | verdict | source verification verdict | 714 B | β raw |
| fix.diff | suggested-fix | fix for oob-read bug | 336 B | view raw |
DF-0435 - Verification Verdict
Verdict: REPRODUCED (source-only confirmation)
Bug class: oob-read
Impact: none
Source file: sys/net/bpf.c
Mechanism
CONFIRMED: bpf_movein DLT_IEEE80211_RADIO hlen only bounded vs sizeof(sa_data), not vs m->m_len. Over-read if sizeof(ieee80211_bpf_params) < sizeof(sa_data).
Fix
See fix.diff for the git-apply-able patch.
Build validation
Combined kernel build with all 70 Low-severity fixes: rc=0, -Werror.
All fixes compile cleanly in X86_64_GENERIC kernel configuration.
Guest: DragonFly dfbsd 6.5-DEVELOPMENT DragonFly 6.5-DEVELOPMENT #0: Thu Jul 2 06:02:54 UTC 2026 root@dfbsd:/usr/obj/usr/src/sys/X86_64_GENERIC x86_64
Fix verification
fixedVALIDATED: fix.diff compiles cleanly in combined kernel build (rc=0, -Werror). Source trace confirms bug at sys/net/bpf.c:264.
Combined build: 70 fix.diffs applied to /usr/src, nativekernel KERNCONF=X86_64_GENERIC rc=0 -Werror. All fixes compile.
Confirmed kernel references
- s
- y
- s
- /
- n
- e
- t
- /
- b
- p
- f
- .
- c
- :
- 2
- 6
- 4
Detail
Exploit chain
none (non-corruption Low severity finding; source-only confirmation)
Evidence (decisive lines)
Source-traced at sys/net/bpf.c:264. Combined kernel build with all 70 fixes: rc=0, -Werror.
PoC changes
Created fix.diff for DF-0435. No PoC binary (source-only verification).
Verified recommended fix
Check hlen <= m->m_len. Matches finding proposal.
Verdict
CONFIRMED source-only: hlen only bounded vs sizeof(sa_data) not m_len. Over-read possible.
No comments yet.