Skip to content

Fix out-of-bounds read in NDP layers parsed from a truncated ICMPv6 message#2192

Open
vsaraikin wants to merge 1 commit into
seladb:masterfrom
vsaraikin:fix/ndp-truncated-header-oob
Open

Fix out-of-bounds read in NDP layers parsed from a truncated ICMPv6 message#2192
vsaraikin wants to merge 1 commit into
seladb:masterfrom
vsaraikin:fix/ndp-truncated-header-oob

Conversation

@vsaraikin

@vsaraikin vsaraikin commented Jul 23, 2026

Copy link
Copy Markdown

parseIcmpV6Layer builds an NDP neighbor solicitation/advertisement layer for ICMPv6 types 135/136 after only checking dataLen >= sizeof(icmpv6hdr) (4 bytes), but both NDP headers are 24 bytes. So a 4-23 byte type 135/136 message still gets parsed as NDP, and getTargetIP() reads the 16-byte target address at offset 8 past the end of the buffer. The option walk hits the same thing: getHeaderLen() - getNdpHeaderLen() is dataLen - 24, which underflows for a short packet. Both are reachable from toString().

Fix adds isDataValid() to the two NDP layers (require the full 24 bytes) and falls back to a plain IcmpV6Layer when the message is too short, same as the GtpV2 guard in #2181.

Testing

Added truncated type 135/136 messages to IcmpV6ParsingTest (rejected by isDataValid, full 24-byte headers still accepted). icmpv6 tests pass.

@vsaraikin
vsaraikin marked this pull request as ready for review July 25, 2026 17:31
@vsaraikin
vsaraikin requested a review from seladb as a code owner July 25, 2026 17:31
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant