Re: [BUG] netfilter: IPv6 conntrack fragment reassembly truncates header offset
From: 성병찬
Date: Tue Sep 29 2026 - 05:43:31 EST
Thanks for the information. I confirmed that Jérémy Jean's existing
patch is identical to the fix I tested. Please treat my patch as
superseded by that patch.
I have attached my self-contained reproducer as repro-v2.c. It only
uses IPv6 loopback (::1) and does not send traffic outside the test
system.
Build:
cc -std=c11 -O2 -Wall -Wextra -Werror \
-o repro-v2 repro-v2.c
The test requires root or CAP_NET_RAW. I ran it in a QEMU guest booted
with:
nf_conntrack.enable_hooks=1
Run:
./repro-v2 1
Expected result on the unmodified kernel:
iteration=1 control_received=yes
iteration=1 boundary_received=no
RESULT: differential observed (control delivered, boundary not delivered)
The reproducer exits with status 0 when the bug is reproduced.
Expected result with Jérémy Jean's patch applied:
iteration=1 control_received=yes
iteration=1 boundary_received=yes
RESULT: control passed but expected boundary drop was not observed
In this case it exits with status 2 because the bug is no longer
reproduced.
I reproduced the unmodified result twice and tested the fixed result
twice on Linux v7.2.8.
The SHA-256 of the attached source is:
511dd29a2c41d0c734bb1369a6ab538a85f2498d92c137802c6775240ca17903
You may add:
Tested-by: 성병찬 <tjdqudcks0424@xxxxxxxxx>
Regards,
Sung Byeongchan
Attachment:
repro-v2.c
Description: Binary data