Re: [PATCH net] ipv6: fix Route Information option length validation
From: Ido Schimmel
Date: Wed Jul 29 2026 - 09:48:48 EST
On Wed, Jul 29, 2026 at 11:47:19AM +0800, Yuejie Shi wrote:
> rt6_route_rcv() validates the Route Information option (RFC 4191) length
> against the prefix length, but both checks are off by one.
>
> rinfo->length is the ND option length in units of 8 octets and it
> *includes* the 8-byte option header, so an option carrying N bytes of
> prefix has length == 1 + N/8. RFC 4191 section 2.3 requires length 3
> when Prefix Length is greater than 64, and 2 or 3 when it is greater
> than 0. The code accepts length >= 2 and length >= 1 respectively.
>
> ipv6_addr_prefix() then copies prefix_len/8 bytes out of rinfo->prefix,
> so a Router Advertisement with (prefix_len=128, length=2) or
> (prefix_len=64, length=1) makes the kernel read up to 8 bytes past the
> end of the option. Those bytes end up in the prefix of the route that
> gets installed, so they are visible to userspace:
>
> # RA with a Route Information option (prefix_len=128, length=2)
> # followed by a source link-layer address option, 01 01 de ad be ef ca fe
> $ ip -6 route show
> 2001:db8:dead:beef:101:dead:beef:cafe via fe80::1234 dev veth0 proto ra
> ^^^^^^^^^^^^^^^^^^ the next option, read out of bounds
>
> When the Route Information option is the last one in the packet, those
> eight bytes come from the skb tail room instead.
>
> Reject the option lengths RFC 4191 does not allow.
>
> Fixes: 70ceb4f53929 ("[IPV6]: ROUTE: Add experimental support for Route Information Option in RA (RFC4191).")
> Cc: stable@xxxxxxxxxxxxxxx
>
Unnecessary blank line
> Signed-off-by: Yuejie Shi <syjcnss@xxxxxxxxx>
Reviewed-by: Ido Schimmel <idosch@xxxxxxxxxx>