Re: [BUG] netfilter: IPv6 conntrack fragment reassembly truncates header offset

From: 성병찬

Date: Tue Sep 29 2026 - 05:43:31 EST



Thanks for the information. I confirmed that Jérémy Jean's existing
patch is identical to the fix I tested. Please treat my patch as
superseded by that patch.

I have attached my self-contained reproducer as repro-v2.c. It only
uses IPv6 loopback (::1) and does not send traffic outside the test
system.

Build:

cc -std=c11 -O2 -Wall -Wextra -Werror \
-o repro-v2 repro-v2.c

The test requires root or CAP_NET_RAW. I ran it in a QEMU guest booted
with:

nf_conntrack.enable_hooks=1

Run:

./repro-v2 1

Expected result on the unmodified kernel:

iteration=1 control_received=yes
iteration=1 boundary_received=no
RESULT: differential observed (control delivered, boundary not delivered)

The reproducer exits with status 0 when the bug is reproduced.

Expected result with Jérémy Jean's patch applied:

iteration=1 control_received=yes
iteration=1 boundary_received=yes
RESULT: control passed but expected boundary drop was not observed

In this case it exits with status 2 because the bug is no longer
reproduced.

I reproduced the unmodified result twice and tested the fixed result
twice on Linux v7.2.8.

The SHA-256 of the attached source is:

511dd29a2c41d0c734bb1369a6ab538a85f2498d92c137802c6775240ca17903

You may add:

Tested-by: 성병찬 <tjdqudcks0424@xxxxxxxxx>

Regards,
Sung Byeongchan

Attachment: repro-v2.c
Description: Binary data