From nobody Thu Jun 25 00:34:01 2026 Received: from mail-qv1-f42.google.com (mail-qv1-f42.google.com [209.85.219.42]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id F1A1E3D904F for ; Mon, 8 Jun 2026 18:15:48 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.42 ARC-Seal: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780942551; cv=none; b=nBorbfeTAJDdd48krhvWBgNmIJiH7gPSsDVTUqXouCZDLxrImOqgXNmgXNLnNgi1IK4SIXmWC1EXtFJyAar73EAB+2oDdv6izBOTTyGz4mEGAw+YFia8iZm3asn+GvjfgFS2dUcI2M19s0HZnuPMaZpOOl7JCvUtOyWyraq+oTA= ARC-Message-Signature: i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1780942551; c=relaxed/simple; bh=nVvJuOvWR1oz6S/HWYlHag1TQ0cRcGNfk3EfBz2+83s=; h=From:To:Cc:Subject:Date:Message-ID:MIME-Version; b=unMOmTl7KFzs1YmvFF76lKUrJ31Xb/sVqD0BEvFUpL6JDWTtZ6PON9tDNKO31nZOVFjYi3lG2vKHj26RkDm1szcSKbzuiEtXf96gbl1pzKSt9QGCIfpSeqFFdKgECjFYFFv0TFQ4RzfBTuquJ6dK5sXAIu+TO7HVr144cqW+nwI= ARC-Authentication-Results: i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=dA4mRX25; arc=none smtp.client-ip=209.85.219.42 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="dA4mRX25" Received: by mail-qv1-f42.google.com with SMTP id 6a1803df08f44-8ce9df48e1bso46643276d6.1 for ; Mon, 08 Jun 2026 11:15:48 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1780942548; x=1781547348; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:from:to:cc:subject:date:message-id:reply-to; bh=ABwQ9Ec6oQdLijfWtetuJzpS6NZcabUv0iN3GAuzHv4=; b=dA4mRX25NqlwnImQOUROiFkRyrVksoI4yfpjYxdkYcH4Q0ub4AjPkI45GKXeEvu67c hDLsxYTbX9CHiOZ98SQCi7um/c6qTkG6C0akgNf0dS0lSO1Ijz8KAZE5AVPQJ1Qouxvm QWwdggzh/BYsKgAJBHEiUiA1sS7U12uAy73W/XdXGYZOgswGgilDeCXevmmu8nLssCU0 EpqXNbyhqoshBCTZ4ci0n1MNwQbty4RhRK9ey4MdWO2dUzwvwwvkuqAjencBlfUgajwv Ch/Yd8CoC/wb0z4d6bU5pVf3WaFioZ+/9KiKr1Weud439++zibboyB1YaHyIHlQtlzQB J4cw== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1780942548; x=1781547348; h=content-transfer-encoding:mime-version:message-id:date:subject:cc :to:from:x-gm-gg:x-gm-message-state:from:to:cc:subject:date :message-id:reply-to; bh=ABwQ9Ec6oQdLijfWtetuJzpS6NZcabUv0iN3GAuzHv4=; b=Ow9zysTtPgO00OqbpS3U7xxTbXpOX3WCm9CyNdcB8Kl66UXWU8KAE2I3Q4SDJxZMO0 4thNO7BUZBLyCR1xmwqC45/B7HdVbePJQJgSSaGt/kTfaghZsi3dcSpt7HEZl+12L9Nu Sa7we/oNZ74Kw6sbeoZsHRZcCV0fyRLCPumtOHJS3XahO4XYLPE90EkM0PzH13mi9Yxg XuTBwMQluF1xMKp9f2gNhgosST1RmJ1JvpKf4Rh6lI69Xi1uQb9nNBln52VrXVdIFjo1 /VcfzAVRiJ9VSrJ1S72Omt53u+3itvkntfUKEDUQBD+JOyZbrlL5PA6zG9Vgs8qlN/a0 u0LQ== X-Forwarded-Encrypted: i=1; AFNElJ+IwyNAjOsxloVXP6i2GOEWLJuh04jVIjMFt1QjldHW28ySPfVMiIAQAYO44I7xc9o/8s2DW8w5FSh+QHQ=@vger.kernel.org X-Gm-Message-State: AOJu0YzzZCcRMq2kWG/gDItmPMpAPILsxH6a+whR9KXw6kWnSkrkb38I djdYGZG9vKAzGN+NlPoWhfAhW3wpX2nKJrAdsclKnkDoYrqoVmg1+YyNl3k/THTn7DQ= X-Gm-Gg: Acq92OGjRUWomSuJ5aRUrONAZRknk5lD9KVGFnP2vGby3zZnmb2dVm1/Uf6j3PPNeBO aQGcjsZCFFFkMT5kyT5RVt0FdGLp9DLHWACFwKPVcyocPRHwGWoDQZxcLJrogRNYbDT0ryn2mDM P72y5Qm6MwRBcqkX6hRtNFxu020+74maQ7NQLBDW9pnsdq5dy9zp9UsYwTSNNeH4T3aX1w0Df2e 46a3T15gAd52BsZMnC+aXSxeZqgKuIDB5gUftrXd+Kidv9n9D43HHuhYbUlMop2xEmG5G1ppsTI e/CLRaggn4a9zW1TVCyj3LYZpMLObYySCmU6pohOjglJD/zmSnFmC7AcCSrxrw7+z9QunsPtxFw hyFkxebB62Sv4/Z/aeQRDMiZIU7cNNbbpgmQkbd4FY7tR0bTgbyzM7mSqlNdgxrKeGCCb24cERq 4Acuoaxk0aym6wgwAvkTKDU3ReuJK04T7SNLc7eA== X-Received: by 2002:ad4:4e72:0:b0:8b8:726a:74d4 with SMTP id 6a1803df08f44-8cee5fcb15amr208894376d6.16.1780942547813; Mon, 08 Jun 2026 11:15:47 -0700 (PDT) Received: from localhost ([161.35.96.86]) by smtp.gmail.com with UTF8SMTPSA id 6a1803df08f44-8cecd2682f8sm172976246d6.43.2026.06.08.11.15.46 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Mon, 08 Jun 2026 11:15:47 -0700 (PDT) From: Samuel Moelius To: Jamal Hadi Salim Cc: Samuel Moelius , Jiri Pirko , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , netdev@vger.kernel.org (open list:TC subsystem), linux-kernel@vger.kernel.org (open list) Subject: [PATCH v2] net/sched: act_nat: only rewrite IPv4 packets Date: Mon, 8 Jun 2026 18:13:49 +0000 Message-ID: <20260608181348.1146175.b644bbba93da.act-nat-non-ipv4@trailofbits.com> X-Mailer: git-send-email 2.43.0 Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: quoted-printable Content-Type: text/plain; charset="utf-8" act_nat can process packets whose protocol is not IPv4 and then interpret the payload as an IPv4 header. Non-IPv4 packets may be modified based on unrelated bytes at the network header offset. The action is documented as IPv4 NAT and should leave other protocols alone. Check the packet protocol before parsing and rewriting the IPv4 header. Do not look through inline VLAN tags, because act_nat does not adjust the network header offset before using ip_hdr(skb). Assisted-by: Codex:gpt-5.5-cyber-preview Signed-off-by: Samuel Moelius --- Changes in v2 - don't corrupt VLAN tags net/sched/act_nat.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/net/sched/act_nat.c b/net/sched/act_nat.c index abb332dee836..cb3e7a415da7 100644 --- a/net/sched/act_nat.c +++ b/net/sched/act_nat.c @@ -142,6 +142,9 @@ TC_INDIRECT_SCOPE int tcf_nat_act(struct sk_buff *skb, egress =3D parms->flags & TCA_NAT_FLAG_EGRESS; =20 noff =3D skb_network_offset(skb); + if (skb_protocol(skb, false) !=3D htons(ETH_P_IP)) + goto out; + if (!pskb_may_pull(skb, sizeof(*iph) + noff)) goto drop; =20 --=20 2.43.0