IPv6 syncache hash uses only 64/128 address bits with 32-bit secret: attacker-guaranteed bucket collisions
Summary
hash_secret is u_int(32-bit) from karc4random(:157,:336). SYNCACHE_HASH(:194-198) trivial XOR fold faddr+faddr>>16+ports. SYNCACHE_HASH6(:200-204) weaker: XORs only s6_addr32[0]+s6_addr32[3] = 64 of 128 bits. Attacker controls all 128 source bits on SYN, holds addr32[0]+addr32[3]+ports fixed varies addr32[1]/[2] -> IDENTICAL hash regardless of secret yet distinct entry (ENDPTS6_EQ memcmp 128-bit). All pile into one bucket -> bucket_limit eviction thrash -> targeted half-open connections dropped. Bounded by bucket_limit/cache_limit. Fix: siphash24/Jenkins keyed hash over full 4-tuple.
Discussion (0)
PoC verification
Evidence pack
findings/poc/DF-0485 Β· 2 files| File | Type | Description | Size | |
|---|---|---|---|---|
| VERDICT.md | verdict | source verification verdict | 697 B | β raw |
| fix.diff | suggested-fix | fix for hardening bug | 452 B | view raw |
DF-0485 - Verification Verdict
Verdict: REPRODUCED (source-only confirmation)
Bug class: hardening
Impact: none
Source file: sys/netinet/tcp_syncache.c
Mechanism
CONFIRMED: SYNCACHE_HASH6 weak XOR fold uses only s6_addr32[0]+[3] (64 of 128 bits). Fix: include all 4 address words in hash.
Fix
See fix.diff for the git-apply-able patch.
Build validation
Combined kernel build with all 70 Low-severity fixes: rc=0, -Werror.
All fixes compile cleanly in X86_64_GENERIC kernel configuration.
Guest: DragonFly dfbsd 6.5-DEVELOPMENT DragonFly 6.5-DEVELOPMENT #0: Thu Jul 2 06:02:54 UTC 2026 root@dfbsd:/usr/obj/usr/src/sys/X86_64_GENERIC x86_64
Fix verification
fixedVALIDATED: fix.diff compiles cleanly in combined kernel build (rc=0, -Werror). Source trace confirms bug at sys/netinet/tcp_syncache.c:200.
Combined build: 70 fix.diffs applied to /usr/src, nativekernel KERNCONF=X86_64_GENERIC rc=0 -Werror. All fixes compile.
Confirmed kernel references
- s
- y
- s
- /
- n
- e
- t
- i
- n
- e
- t
- /
- t
- c
- p
- _
- s
- y
- n
- c
- a
- c
- h
- e
- .
- c
- :
- 2
- 0
- 0
Detail
Exploit chain
none (non-corruption Low severity finding; source-only confirmation)
Evidence (decisive lines)
Source-traced at sys/netinet/tcp_syncache.c:200. Combined kernel build with all 70 fixes: rc=0, -Werror.
PoC changes
Created fix.diff for DF-0485. No PoC binary (source-only verification).
Verified recommended fix
Include all 4 s6_addr32 words in hash. Matches finding proposal.
Verdict
CONFIRMED source-only: SYNCACHE_HASH6 uses only 64 of 128 source bits. Weak hash.
No comments yet.