Skip to content

Fix IndexError/struct.error when scanning IPv6 Hop-by-Hop header for a Jumbo option - #5208

Open
AbdaullahAG wants to merge 1 commit into
secdev:masterfrom
AbdaullahAG:fix-jumbo-option-bounds
Open

AbdaullahAG wants to merge 1 commit into
secdev:masterfrom
AbdaullahAG:fix-jumbo-option-bounds

Conversation

@AbdaullahAG

Copy link
Copy Markdown

Description

IPv6.extract_padding looks for a Jumbo option in the Hop-by-Hop header with while offset <= len(data). When no Jumbo option is found and len(data) equals an offset visited by the loop, data[offset] raises IndexError. When an 0xc2 type byte is found with fewer than 6 bytes remaining, struct.unpack raises struct.error.

scapy/scapy/layers/inet6.py

Lines 366 to 370 in 7daa15d

offset = 4 * idx + 2
while offset <= len(data):
opt_type = data[offset]
if opt_type == 0xc2: # Jumbo option
jumbo_len = struct.unpack("I", data[offset + 2:offset + 2 + 4])[0] # noqa: E501

from scapy.all import IPv6

hdr = bytes(IPv6(nh=0, plen=0))
IPv6(hdr + b"\x3b\x00\x01\x00\x00\x00\x00\x00\x00\x00")  # IndexError
IPv6(hdr + b"\x3b\x00\x01\x00\x00\x00\xc2\x04\x00\x00")  # struct.error

The loop now requires 6 bytes (type, length, 4-byte value) to remain. A regression test is added to test/scapy/layers/inet6.uts.

Fix an out-of-bounds read when parsing IPv6 options where an Option 194 (Jumbo Payload) payload is shorter than expected.

AI-Assisted: yes (to find the bug, code written manually)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant