NetBSD-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: kern/60487: netinet6: fragment accounting leak



The following reply was made to PR kern/60487; it has been noted by GNATS.

From: Taylor R Campbell <riastradh%NetBSD.org@localhost>
To: gnats-bugs%NetBSD.org@localhost, netbsd-bugs%NetBSD.org@localhost
Cc: 
Subject: Re: kern/60487: netinet6: fragment accounting leak
Date: Thu, 23 Jul 2026 21:09:11 +0000

 Another report forwarded to us describes a similar accounting leak for
 frag6_nfragpackets:
 
     267 	if (q6 == &ip6q) {
     268 		/*
     269 		 * the first fragment to arrive, create a reassembly queue.
     270 		 */
     271 		first_frag = 1;
 ...
     284 		frag6_nfragpackets++;
     285 
     286 		q6 = kmem_intr_zalloc(sizeof(struct ip6q), KM_NOSLEEP);
     287 		if (q6 == NULL) {
     288 			goto dropfrag;
     289 		}
 ...
     301 	}
 ...
     313 	/*
     314 	 * Check that the reassembled packet would not exceed 65535 bytes
     315 	 * in size. If it would exceed, discard the fragment and return an
     316 	 * ICMP error.
     317 	 */
     318 	if (q6->ip6q_unfrglen >= 0) {
     319 		/* The 1st fragment has already arrived. */
     320 		if (q6->ip6q_unfrglen + fragoff + frgpartlen > IPV6_MAXPACKET) {
     321 			mutex_exit(&frag6_lock);
     322 			icmp6_error(m, ICMP6_PARAM_PROB, ICMP6_PARAMPROB_HEADER,
     323 			    offset - sizeof(struct ip6_frag) +
     324 			    offsetof(struct ip6_frag, ip6f_offlg));
     325 			goto done;
     326 		}
     327 	} else if (fragoff + frgpartlen > IPV6_MAXPACKET) {
     328 		mutex_exit(&frag6_lock);
     329 		icmp6_error(m, ICMP6_PARAM_PROB, ICMP6_PARAMPROB_HEADER,
     330 		    offset - sizeof(struct ip6_frag) +
     331 		    offsetof(struct ip6_frag, ip6f_offlg));
     332 		goto done;
     333 	}
 
 https://nxr.netbsd.org/xref/src/sys/netinet6/frag6.c?r=1.79#267
 
 In these error branches, the claim is that frag6_nfragpackets leaks.
 So perhaps we should have
 
 +	if (first_frag)
 +		frag6_dropfrag(q6);
  	goto done;
 
 in these branches.
 



Home | Main Index | Thread Index | Old Index