Re: [PATCH net-next 3/5] bridge: Validate NS/NA messages using ndisc_check_ns_na()
From: Nikolay Aleksandrov
Date: Mon Jul 20 2026 - 05:15:08 EST
On 19/07/2026 16:34, Danielle Ratson wrote:
The bridge performs neighbor suppression by snooping NS/NA messages, but
previously only checked the ICMPv6 type and code. This leaves it open to
acting on malformed or spoofed packets that any RFC-compliant node should
reject.
Wire br_is_nd_neigh_msg() into the new ndisc_check_ns_na() helper, which
enforces the full RFC 4861 section 7.1.1/7.1.2 receive validation:
hop limit of 255, valid checksum, correct code, and type-specific rules
(NS target not multicast; NA solicited flag clear for multicast
destinations).
MLD messages are already validated by ipv6_mc_check_mld() before the
bridge acts on them; this brings NS/NA to the same standard.
As a side effect, the skb parameter of br_is_nd_neigh_msg() changes from
const to non-const, since ndisc_check_ns_na() may reallocate the skb head
via pskb_may_pull() and sets the transport header. The returned pointer is
now derived from skb_transport_header() rather than a direct cast.
Reviewed-by: Petr Machata <petrm@xxxxxxxxxx>
Signed-off-by: Danielle Ratson <danieller@xxxxxxxxxx>
---
net/bridge/br_arp_nd_proxy.c | 11 ++++-------
net/bridge/br_private.h | 2 +-
2 files changed, 5 insertions(+), 8 deletions(-)
Acked-by: Nikolay Aleksandrov <razor@xxxxxxxxxxxxx>