[PATCH net] ipv6: rpl: unclone the skb before modifying the packet
From: Andrea Mayer
Date: Thu Oct 01 2026 - 14:34:59 EST
ipv6_rpl_srh_rcv() modifies the packet data, such as Segments Left and
the destination address, without checking whether the skb is cloned.
The skb may be cloned, for example by an AF_PACKET socket receiving on
the ingress device. ipv6_rpl_srh_rcv() then writes into the packet data
shared with the clone. A read from that socket can return the modified
packet instead of the received one.
The only pskb_expand_head() in the function runs after Segments Left and
the destination address are written, and only when Segments Left reaches
0 or there is not enough headroom.
Call pskb_expand_head() on a cloned skb before the packet is modified
(i.e., before Segments Left is decremented), as ipv6_srh_rcv() does.
On failure, drop the packet with SKB_DROP_REASON_NOMEM.
Fixes: a2f4c143d76b ("ipv6: rpl: Fix Route of Death.")
Reported-by: Sashiko <sashiko-bot@xxxxxxxxxx>
Closes: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260925133807.32-1-andrea.mayer%40uniroma2.it
Signed-off-by: Andrea Mayer <andrea.mayer@xxxxxxxxxxx>
---
net/ipv6/exthdrs.c | 11 +++++++++++
1 file changed, 11 insertions(+)
diff --git a/net/ipv6/exthdrs.c b/net/ipv6/exthdrs.c
index 09a4552f7f08..8fcf18e6114d 100644
--- a/net/ipv6/exthdrs.c
+++ b/net/ipv6/exthdrs.c
@@ -548,6 +548,17 @@ static int ipv6_rpl_srh_rcv(struct sk_buff *skb, struct inet6_dev *idev)
return -1;
}
+ if (skb_cloned(skb)) {
+ if (pskb_expand_head(skb, 0, 0, GFP_ATOMIC)) {
+ __IP6_INC_STATS(net, ip6_dst_idev(skb_dst(skb)),
+ IPSTATS_MIB_OUTDISCARDS);
+ kfree_skb_reason(skb, SKB_DROP_REASON_NOMEM);
+ return -1;
+ }
+
+ hdr = (struct ipv6_rpl_sr_hdr *)skb_transport_header(skb);
+ }
+
hdr->segments_left--;
i = n - hdr->segments_left;
--
2.43.0