Skip to content

fix(cve): CVE-2026-31911 - CVE-2026-31911: Fail opcodes safely in the BPF interpreter. - #7

Merged
Zeno-sole merged 10 commits into
masterfrom
fix-cve/CVE-2026-31911
Sep 21, 2026
Merged

Zeno-sole merged 10 commits into
masterfrom
fix-cve/CVE-2026-31911

Conversation

@deepin-ci-robot

@deepin-ci-robot deepin-ci-robot commented Sep 15, 2026 •

Copy link
Copy Markdown
Contributor

CVE: CVE-2026-31911 (medium) - Fail opcodes safely in the BPF interpreter.
Upstream: https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9.patch

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-18238 (medium) - Fix RPCAP_MSG_PACKET validation
Upstream: the-tcpdump-group/libpcap@b9590d4

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-6244 (medium) - Avoid division by zero via pcap_offline_filter()
Upstream: the-tcpdump-group/libpcap@0b2b1ad

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b


CVE: CVE-2026-31912 (medium) - Mind the program bounds in pcap_offline_filter()
Upstream: the-tcpdump-group/libpcap@d3f358d

Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b

… BPF interpreter.

CVE: CVE-2026-31911 (medium) - Fail opcodes safely in the BPF interpreter.
Upstream: https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
@deepin-ci-robot deepin-ci-robot added cve CVE vulnerability fix generated-by-ai Generated by AI labels Sep 15, 2026
@github-actions

Copy link
Copy Markdown

TAG Bot

TAG: 1.10.1-4deepin4
EXISTED: no
DISTRIBUTION: unstable

@deepin-ci-robot

Copy link
Copy Markdown
Contributor Author

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign liujianqiang-niu for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

deepin-ci-robot and others added 6 commits September 16, 2026 06:21
…ation.

CVE: CVE-2026-18238 (medium) - Fix RPCAP_MSG_PACKET validation
Upstream: the-tcpdump-group/libpcap@b9590d4

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…cap_offline_filter()

CVE: CVE-2026-6244 (medium) - Avoid division by zero via pcap_offline_filter()
Upstream: the-tcpdump-group/libpcap@0b2b1ad

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
…_offline_filter()

CVE: CVE-2026-6554 (medium) - Limit "ja L" looping in pcap_offline_filter()
Upstream: the-tcpdump-group/libpcap@ff3c834

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
CVE: CVE-2026-6554 - 兼容性适配修改:无额外兼容性问题,CVE patch 已正确应用

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
… interpreter.

CVE: CVE-2026-0799 (high) - Access M[] safely in the BPF interpreter.
Upstream: https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7.patch

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
@Zeno-sole

Copy link
Copy Markdown
Contributor

/integrate

@github-actions

Copy link
Copy Markdown

AutoIntegrationPr Bot
auto integrate with pr url: deepin-community/Repository-Integration#4576
PrNumber: 4576
PrBranch: auto-integration-35499716307

deepin-ci-robot and others added 2 commits September 20, 2026 21:23
… pcap_offline_filter()

CVE: CVE-2026-31912 (medium) - Mind the program bounds in pcap_offline_filter()
Upstream: the-tcpdump-group/libpcap@d3f358d

Co-authored-by: hudeng <hudeng@deepin.org>
Generated-By: qwen3.6-35b
CVE: CVE-2026-31912 - 兼容性适配修改:上游补丁给 pcap_filter() /
pcap_filter_with_aux_data() 增加了 proglen 参数,但 1.10.1 基线上还有一批
上游 master 已不存在的调用点没有一起更新,导致 bpf_filter.c 编译失败:

  ./bpf_filter.c:599:16: error: too few arguments to function 'pcap_filter'

本次补齐这些调用点:
  * bpf_filter.c 中废弃的 bpf_filter() 兼容包装函数。该接口无法得知程序
    长度,与上游一致传入 BPF_MAXINSNS;
  * Solaris/IRIX (pcap-nit.c, pcap-snit.c, pcap-snoop.c, pcap-pf.c)、
    DOS (pcap-dos.c)、IBM RT PC (pcap-enet.c)、Windows/AirPcap
    (pcap-airpcap.c)、Septel (pcap-septel.c) 与 TC (pcap-tc.c) 后端。

Co-authored-by: hudeng <hudeng@deepin.org>
@hudeng-go

Copy link
Copy Markdown
Contributor

构建失败根因

debian/patches/CVE-2026-31912.patch 给 pcap_filter() / pcap_filter_with_aux_data() 增加了 proglen(程序长度)参数 —— 这是上游 commit d3f358d3 的核心改动,其提交说明明确要求 "Update all incoming code paths to specify the length"。

但该 patch 是按上游 master 的代码形态生成的,而 libpcap 1.10.1 基线上还存在一批上游 master 早已删除、因而没有出现在上游 diff 里的调用点。它们没有被一起更新,仍以旧的 4 参数形式调用新的 5 参数函数:

./bpf_filter.c:599:16: error: too few arguments to function 'pcap_filter'
  599 |         return pcap_filter(pc, p, wirelen, buflen);
  440 | pcap_filter(const struct bpf_insn *pc, const u_int proglen, const u_char *p,

bpf_filter.c 属于 COMMON_C_SRC,所有架构都会编译,因此构建在第一个目标文件上即告失败。

修复

补齐全部遗漏调用点:

文件 说明
bpf_filter.c 废弃的 bpf_filter() 兼容包装函数。其签名没有程序长度,按上游做法传入 BPF_MAXINSNS,并补上上游新增的 deprecated 注释
pcap-nit.c / pcap-snit.c / pcap-snoop.c / pcap-pf.c Solaris / IRIX 后端
pcap-dos.c DOS 后端
pcap-enet.c IBM RT PC 后端
pcap-airpcap.c Windows / AirPcap 后端
pcap-septel.c Septel 后端
pcap-tc.c TC 后端

这些文件在 Linux 上不会被编译,但既然补丁改动了公共函数签名,就应把源码树中的调用点一并补齐,否则包内代码不自洽(在对应平台上无法编译)。同时更新了 DEP-3 头的 Description 与 Last-Update。

验证

  • 本地 A/B:用旧 patch 编译 bpf_filter.c,精确复现 OBS 报错(bpf_filter.c:440 / 599,同样的 note);用新 patch 编译无 error 无 warning。
  • 覆盖面:本地把 OBS 实际编译的 19 个目标文件全部编译,17 个通过,其余 2 个仅因本机缺 libbluetooth 头文件(OBS 上本来就编译通过)。
  • 功能:直接调用 pcap_filter() 验证 —— 截断程序(无 BPF_RET)返回 0,越界条件跳转返回 0,合法程序返回 0xffffffff,废弃的 bpf_filter() 包装函数工作正常。
  • OBS:deepin:CI:deepin-community:libpcap:PR-7 的 x86_64 与 aarch64 均 published,日志中 too few arguments 出现 0 次。

另外提一句(与本次编译错误无关):tide 报 Not mergeable. PR can't be rebased,原因是分支上存在 merge commit d2554f4(Merge branch 'master' into fix-cve/CVE-2026-31911),GitHub 的 rebase 合并方式不接受带 merge commit 的分支。如需合并,需要先把该分支 rebase 到 master 上。

Complete the CVE-2026-31912 backport with the upstream BPF_JMP|BPF_JA
bounds check, which this backport had dropped.  Without it the loop-top
check only catches a program counter that runs past the end of the
program, so a program that reached the interpreter through
pcap_offline_filter() or the deprecated bpf_filter() could still move the
program counter before the start of the filter program and read out of
bounds there.  Upstream's own regression case for this CVE
(ja_neg_2_OOB: BPF_JMP|BPF_JA with k == -2 and bf_len == 2) made the
interpreter SIGSEGV before this change and is rejected now.

Also backport upstream commit 1d1ea168 ("For "lsh" and "rsh" guard "#k"
as well").  "lsh x" and "rsh x" were already guarded, but "lsh #k" and
"rsh #k" with k > 31 shift by an amount that is undefined behaviour in C;
UBSan reports it as "shift exponent 32 is too large for 32-bit type
'unsigned int'".  Programs generated by libpcap never have k > 31, but
programs that come from an external source via pcap_offline_filter() can
have any value.  The upstream commit rejects such instructions in
pcap_valid_insn(), which comes from commit 19718105 and is not part of
this backport, so that hunk is applied to the equivalent place in
pcap_validate_filter() instead.

Log: Backported the missing BPF_JA bounds check and the lsh/rsh "#k" guard

Influence:
1. Build libpcap and run the test suite
2. Feed a BPF_JMP|BPF_JA with a large negative k through
   pcap_offline_filter() and check the packet is rejected, not a crash
3. Compile filters that use shifts and check they still validate
4. Check that pcap_validate_filter() rejects "lsh #32" and accepts
   "lsh #31"
5. Check that the whole patch series still applies with quilt push -a

fix: 回移 BPF_JA 越界检查与 lsh/rsh "#k" 移位保护

补全 CVE-2026-31912 的回移:原补丁漏掉了上游针对 BPF_JMP|BPF_JA 的越界
检查。缺少该检查时,循环顶部的判断只能拦住程序计数器越过程序末尾的情况,
经 pcap_offline_filter() 或已废弃的 bpf_filter() 进入解释器的程序仍可把
程序计数器移到过滤器程序之前,并在那里越界读取。上游为该 CVE 自带的回归
用例 ja_neg_2_OOB(BPF_JMP|BPF_JA 的 k == -2、bf_len == 2)在修改前会使
解释器 SIGSEGV,修改后正常返回"不匹配"。

同时回移上游 commit 1d1ea168("For "lsh" and "rsh" guard "#k" as well")。
"lsh x" / "rsh x" 原本就有保护,但 k > 31 的 "lsh #k" / "rsh #k" 会移位
超过 31 位,在 C 中是未定义行为,UBSan 报 "shift exponent 32 is too large
for 32-bit type 'unsigned int'"。libpcap 自己生成的程序不会有 k > 31,但经
pcap_offline_filter() 传入的外部程序可以是任意值。该上游提交还会在
pcap_valid_insn() 中拒绝这类指令,而 pcap_valid_insn() 来自未回移的
commit 19718105,因此该 hunk 改写为 pcap_validate_filter() 中对应的位置。

Log: 回移漏掉的 BPF_JA 越界检查与 lsh/rsh "#k" 移位保护

Influence:
1. 构建 libpcap 并运行测试
2. 用大负偏移的 BPF_JMP|BPF_JA 调用 pcap_offline_filter(),确认拒绝报文
   而不是崩溃
3. 编译使用移位的过滤器,确认仍能通过校验
4. 确认 pcap_validate_filter() 拒绝 "lsh #32"、接受 "lsh #31"
5. 确认补丁序列仍可被 quilt push -a 干净应用

repo: libpcap #fix-cve/CVE-2026-31911
@Zeno-sole

Copy link
Copy Markdown
Contributor

/integrate

@Zeno-sole
Zeno-sole merged commit 85a1928 into master Sep 21, 2026
4 of 6 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

cve CVE vulnerability fix generated-by-ai Generated by AI

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants