NetBSD-Bugs archive
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]
Re: kern/60487: netinet6: fragment accounting leak
The following reply was made to PR kern/60487; it has been noted by GNATS.
From: Taylor R Campbell <riastradh%NetBSD.org@localhost>
To: gnats-bugs%NetBSD.org@localhost, netbsd-bugs%NetBSD.org@localhost
Cc:
Subject: Re: kern/60487: netinet6: fragment accounting leak
Date: Thu, 23 Jul 2026 21:09:11 +0000
Another report forwarded to us describes a similar accounting leak for
frag6_nfragpackets:
267 if (q6 == &ip6q) {
268 /*
269 * the first fragment to arrive, create a reassembly queue.
270 */
271 first_frag = 1;
...
284 frag6_nfragpackets++;
285
286 q6 = kmem_intr_zalloc(sizeof(struct ip6q), KM_NOSLEEP);
287 if (q6 == NULL) {
288 goto dropfrag;
289 }
...
301 }
...
313 /*
314 * Check that the reassembled packet would not exceed 65535 bytes
315 * in size. If it would exceed, discard the fragment and return an
316 * ICMP error.
317 */
318 if (q6->ip6q_unfrglen >= 0) {
319 /* The 1st fragment has already arrived. */
320 if (q6->ip6q_unfrglen + fragoff + frgpartlen > IPV6_MAXPACKET) {
321 mutex_exit(&frag6_lock);
322 icmp6_error(m, ICMP6_PARAM_PROB, ICMP6_PARAMPROB_HEADER,
323 offset - sizeof(struct ip6_frag) +
324 offsetof(struct ip6_frag, ip6f_offlg));
325 goto done;
326 }
327 } else if (fragoff + frgpartlen > IPV6_MAXPACKET) {
328 mutex_exit(&frag6_lock);
329 icmp6_error(m, ICMP6_PARAM_PROB, ICMP6_PARAMPROB_HEADER,
330 offset - sizeof(struct ip6_frag) +
331 offsetof(struct ip6_frag, ip6f_offlg));
332 goto done;
333 }
https://nxr.netbsd.org/xref/src/sys/netinet6/frag6.c?r=1.79#267
In these error branches, the claim is that frag6_nfragpackets leaks.
So perhaps we should have
+ if (first_frag)
+ frag6_dropfrag(q6);
goto done;
in these branches.
Home |
Main Index |
Thread Index |
Old Index