Re: [PATCH net-next v2 0/5] bridge: Validate and clean up IPv6 neighbour suppression

From: patchwork-bot+netdevbpf

Date: Fri Aug 07 2026 - 19:41:09 EST


Hello:

This series was applied to netdev/net-next.git (main)
by Jakub Kicinski <kuba@xxxxxxxxxx>:

On Mon, 3 Aug 2026 14:25:00 +0300 you wrote:
> The bridge implements IPv6 neighbour suppression by snooping Neighbour
> Solicitation and Neighbour Advertisement messages, but it previously only
> checked the ICMPv6 type and code before acting on them. This leaves it
> open to acting on malformed or spoofed packets that any RFC 4861 compliant
> node should reject, and the option parsing in br_nd_send() open-codes a
> loop that has historically been a source of bugs.
>
> [...]

Here is the summary with links:
- [net-next,v2,1/5] bridge: Use direct pointer in br_is_nd_neigh_msg()
https://git.kernel.org/netdev/net-next/c/2cad8e3d9d94
- [net-next,v2,2/5] ipv6: ndisc: Add ndisc_check_ns_na() validation helper
https://git.kernel.org/netdev/net-next/c/9dfa6cca8959
- [net-next,v2,3/5] bridge: Validate NS/NA messages using ndisc_check_ns_na()
https://git.kernel.org/netdev/net-next/c/18668f4747c9
- [net-next,v2,4/5] bridge: Linearize skb once the ND message type is validated
https://git.kernel.org/netdev/net-next/c/67b14d6e36cf
- [net-next,v2,5/5] bridge: Use ndisc_parse_options() to parse ND options in br_nd_send()
https://git.kernel.org/netdev/net-next/c/7445aaa9fe6d

You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html