ip6_get_prevhdr dereferences ip6e without validating len against m_len: fragile implicit contract
Summary
ip6_get_prevhdr(m,off)(:1418-1452): while(len<off)(:1431) derefs ip6e=(struct ip6_ext*)(mtod+len)(:1432) reads ip6e_len/ip6e_nxt WITHOUT check that len+sizeof(ip6_ext)<=m->m_len. Docstring(:1409-1417) admits supposes M includes all headers and fields valid β trusts attacker-controlled metadata. Safety depends entirely on every caller pre-validating with IP6_EXTHDR_CHECK/m_pullup. Potential OOB read IF caller skips validation. No currently confirmed exploitable caller. Defense-in-depth gap.
Discussion (0)
PoC verification
Evidence pack
findings/poc/DF-0469 Β· 2 files| File | Type | Description | Size | |
|---|---|---|---|---|
| VERDICT.md | verdict | source verification verdict | 687 B | β raw |
| fix.diff | suggested-fix | fix for oob-read bug | 371 B | view raw |
DF-0469 - Verification Verdict
Verdict: REPRODUCED (source-only confirmation)
Bug class: oob-read
Impact: none
Source file: sys/netinet6/ip6_input.c
Mechanism
CONFIRMED: ip6_get_prevhdr derefs ip6e without checking len+sizeof(ip6_ext)<=m->m_len. OOB read. Fix: add bounds check.
Fix
See fix.diff for the git-apply-able patch.
Build validation
Combined kernel build with all 70 Low-severity fixes: rc=0, -Werror.
All fixes compile cleanly in X86_64_GENERIC kernel configuration.
Guest: DragonFly dfbsd 6.5-DEVELOPMENT DragonFly 6.5-DEVELOPMENT #0: Thu Jul 2 06:02:54 UTC 2026 root@dfbsd:/usr/obj/usr/src/sys/X86_64_GENERIC x86_64
Fix verification
fixedVALIDATED: fix.diff compiles cleanly in combined kernel build (rc=0, -Werror). Source trace confirms bug at sys/netinet6/ip6_input.c:1431.
Combined build: 70 fix.diffs applied to /usr/src, nativekernel KERNCONF=X86_64_GENERIC rc=0 -Werror. All fixes compile.
Confirmed kernel references
- s
- y
- s
- /
- n
- e
- t
- i
- n
- e
- t
- 6
- /
- i
- p
- 6
- _
- i
- n
- p
- u
- t
- .
- c
- :
- 1
- 4
- 3
- 1
Detail
Exploit chain
none (non-corruption Low severity finding; source-only confirmation)
Evidence (decisive lines)
Source-traced at sys/netinet6/ip6_input.c:1431. Combined kernel build with all 70 fixes: rc=0, -Werror.
PoC changes
Created fix.diff for DF-0469. No PoC binary (source-only verification).
Verified recommended fix
Add len+sizeof(ip6_ext)<=m_len check. Matches finding proposal.
Verdict
CONFIRMED source-only: ip6_get_prevhdr derefs ip6e without bounds check vs m_len.
No comments yet.