On Tue, 28 Jul 2026 08:50:07 +0200, Shahriyar Jalayeri wrote:
> __net_defragment() reassembles IP fragments into the static buffer
> pkt_buff[CONFIG_NET_MAXDEFRAG].  The bounds check
> 
>       if (start + len > IP_MAXUDP)
>               return NULL;
> 
> only covers the fragment data copy.  The split-hole and move-hole
> branches additionally write an 8-byte struct hole via "*newh = *h" at
> newh = thisfrag + len / 8, which can land up to sizeof(struct hole)
> bytes past the end of pkt_buff.  A single fragment with a non-zero
> fragment offset and the More-Fragments flag set reaches this path, so
> a crafted fragment received during netboot overflows the buffer.
> 
> [...]

Applied to u-boot-net branch for-main, thanks!

[1/2] net: fix out-of-bounds write in IP fragment reassembly
      commit: 04ca915d5bf39dda5d1bce62d04d2b59d293c5b9
[2/2] test: net: add regression test for IP reassembly overflow
      commit: 7946774a0feb40a4abc71e749e61071ffce56979

Best regards,
-- 
Jerome Forissier <[email protected]>

Reply via email to