Back

HIGH

netfilter: conntrack: dccp: copy entire header to stack buffer, not just basic one

Published Sep 16, 2025

Description

Eric Dumazet says: nf_conntrack_dccp_packet() has an unique:

dh = skb_header_pointer(skb, dataoff, sizeof(_dh), &_dh);

And nothing more is 'pulled' from the packet, depending on the content. dh->dccph_doff, and/or dh->dccph_x ...) So dccp_ack_seq() is happily reading stuff past the _dh buffer.

BUG: KASAN: stack-out-of-bounds in nf_conntrack_dccp_packet+0x1134/0x11c0 Read of size 4 at addr ffff000128f66e0c by task syz-executor.2/29371 [..]

Fix this by increasing the stack buffer to also include room for the extra sequence numbers and all the known dccp packet type headers, then pull again after the initial validation of the basic header.

While at it, mark packets invalid that lack 48bit sequence bit but where RFC says the type MUST use them.

Compile tested only.

v2: first skb_header_pointer() now needs to adjust the size to only pull the generic header. (Eric)

Heads-up: I intend to remove dccp conntrack support later this year.

Affected products

Remediation

Red Hat statement

This vulnerability is rated Moderate for Red Hat Enterprise Linux. The flaw is a stack-out-of-bounds read in the netfilter DCCP connection tracking module. Exploitation requires an attacker to send specially crafted DCCP packets to a system with the `nf_conntrack_dccp` module loaded. The vulnerability's impact is primarily on availability, since a malformed packet can lead to a warning or panic, though it can also pose a potential (though unlikely) risk to confidentiality, since kernel stack values could be exposed indirectly through side channels or other error-dependent behaviors.

References (12)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Sep 16, 2025
Updated Aug 5, 2026
Reserved Sep 16, 2025
CISA Vulnrichment
Updated Jan 14, 2026
NVD
Status Modified
Modified Aug 4, 2026
Red Hat
Severity Moderate
Public date Sep 16, 2025