Page MenuHomeFreeBSD

nd6: Do not allocate an ifaddr for the interface ID in in6_ifadd()
ClosedPublic

Authored by rcm on Thu, Oct 8, 7:53 PM.
Tags
None
Referenced Files
F175261908: D60488.id189128.diff
Fri, Oct 9, 1:11 PM
F175261199: D60488.diff
Fri, Oct 9, 12:58 PM
F175226465: D60488.diff
Fri, Oct 9, 6:21 AM
F175187345: D60488.diff
Thu, Oct 8, 11:07 PM
F175187327: D60488.diff
Thu, Oct 8, 11:06 PM

Details

Summary

Without a suitable link-local address, in6_ifadd() obtains the
interface identifier from in6_get_ifid(). It wrote the result into a
freshly allocated struct in6_ifaddr, M_NOWAIT since the function runs
in the network epoch, so SLAAC could fail under memory pressure over a
16 byte scratch buffer.

Write the identifier into the on-stack address the rest of the function
uses instead. Zero it first, in6_get_ifid() only fills in the low 64
bits, as the M_ZERO allocation did. Track which path provided the
identifier with a flag instead of a pointer into the ifaddr, so each
path releases its own reference.

Fixes: 9e792f7ef729 ("sys/netinet6: Fix SLAAC for interfaces with no /64 LL address")
Fixes: f9fc93690aef ("sys/netinet6: fix memory corruption in in6_ifadd")
MFC after: 2 weeks
Sponsored by: Rubicon Communications, LLC ("Netgate")

Test Plan

No functional change intended

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable