fix(cve): CVE-2026-31911 - CVE-2026-31911: Fail opcodes safely in the BPF interpreter. - #7
Conversation
… BPF interpreter. CVE: CVE-2026-31911 (medium) - Fail opcodes safely in the BPF interpreter. Upstream: https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9.patch Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
|
TAG Bot TAG: 1.10.1-4deepin4 |
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
…ation. CVE: CVE-2026-18238 (medium) - Fix RPCAP_MSG_PACKET validation Upstream: the-tcpdump-group/libpcap@b9590d4 Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
…cap_offline_filter() CVE: CVE-2026-6244 (medium) - Avoid division by zero via pcap_offline_filter() Upstream: the-tcpdump-group/libpcap@0b2b1ad Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
…_offline_filter() CVE: CVE-2026-6554 (medium) - Limit "ja L" looping in pcap_offline_filter() Upstream: the-tcpdump-group/libpcap@ff3c834 Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
CVE: CVE-2026-6554 - 兼容性适配修改:无额外兼容性问题,CVE patch 已正确应用 Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
… interpreter. CVE: CVE-2026-0799 (high) - Access M[] safely in the BPF interpreter. Upstream: https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7.patch Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
|
/integrate |
|
AutoIntegrationPr Bot |
… pcap_offline_filter() CVE: CVE-2026-31912 (medium) - Mind the program bounds in pcap_offline_filter() Upstream: the-tcpdump-group/libpcap@d3f358d Co-authored-by: hudeng <hudeng@deepin.org> Generated-By: qwen3.6-35b
CVE: CVE-2026-31912 - 兼容性适配修改:上游补丁给 pcap_filter() / pcap_filter_with_aux_data() 增加了 proglen 参数,但 1.10.1 基线上还有一批 上游 master 已不存在的调用点没有一起更新,导致 bpf_filter.c 编译失败: ./bpf_filter.c:599:16: error: too few arguments to function 'pcap_filter' 本次补齐这些调用点: * bpf_filter.c 中废弃的 bpf_filter() 兼容包装函数。该接口无法得知程序 长度,与上游一致传入 BPF_MAXINSNS; * Solaris/IRIX (pcap-nit.c, pcap-snit.c, pcap-snoop.c, pcap-pf.c)、 DOS (pcap-dos.c)、IBM RT PC (pcap-enet.c)、Windows/AirPcap (pcap-airpcap.c)、Septel (pcap-septel.c) 与 TC (pcap-tc.c) 后端。 Co-authored-by: hudeng <hudeng@deepin.org>
构建失败根因
但该 patch 是按上游 master 的代码形态生成的,而 libpcap 1.10.1 基线上还存在一批上游 master 早已删除、因而没有出现在上游 diff 里的调用点。它们没有被一起更新,仍以旧的 4 参数形式调用新的 5 参数函数:
修复补齐全部遗漏调用点:
这些文件在 Linux 上不会被编译,但既然补丁改动了公共函数签名,就应把源码树中的调用点一并补齐,否则包内代码不自洽(在对应平台上无法编译)。同时更新了 DEP-3 头的 验证
另外提一句(与本次编译错误无关): |
Complete the CVE-2026-31912 backport with the upstream BPF_JMP|BPF_JA bounds check, which this backport had dropped. Without it the loop-top check only catches a program counter that runs past the end of the program, so a program that reached the interpreter through pcap_offline_filter() or the deprecated bpf_filter() could still move the program counter before the start of the filter program and read out of bounds there. Upstream's own regression case for this CVE (ja_neg_2_OOB: BPF_JMP|BPF_JA with k == -2 and bf_len == 2) made the interpreter SIGSEGV before this change and is rejected now. Also backport upstream commit 1d1ea168 ("For "lsh" and "rsh" guard "#k" as well"). "lsh x" and "rsh x" were already guarded, but "lsh #k" and "rsh #k" with k > 31 shift by an amount that is undefined behaviour in C; UBSan reports it as "shift exponent 32 is too large for 32-bit type 'unsigned int'". Programs generated by libpcap never have k > 31, but programs that come from an external source via pcap_offline_filter() can have any value. The upstream commit rejects such instructions in pcap_valid_insn(), which comes from commit 19718105 and is not part of this backport, so that hunk is applied to the equivalent place in pcap_validate_filter() instead. Log: Backported the missing BPF_JA bounds check and the lsh/rsh "#k" guard Influence: 1. Build libpcap and run the test suite 2. Feed a BPF_JMP|BPF_JA with a large negative k through pcap_offline_filter() and check the packet is rejected, not a crash 3. Compile filters that use shifts and check they still validate 4. Check that pcap_validate_filter() rejects "lsh #32" and accepts "lsh #31" 5. Check that the whole patch series still applies with quilt push -a fix: 回移 BPF_JA 越界检查与 lsh/rsh "#k" 移位保护 补全 CVE-2026-31912 的回移:原补丁漏掉了上游针对 BPF_JMP|BPF_JA 的越界 检查。缺少该检查时,循环顶部的判断只能拦住程序计数器越过程序末尾的情况, 经 pcap_offline_filter() 或已废弃的 bpf_filter() 进入解释器的程序仍可把 程序计数器移到过滤器程序之前,并在那里越界读取。上游为该 CVE 自带的回归 用例 ja_neg_2_OOB(BPF_JMP|BPF_JA 的 k == -2、bf_len == 2)在修改前会使 解释器 SIGSEGV,修改后正常返回"不匹配"。 同时回移上游 commit 1d1ea168("For "lsh" and "rsh" guard "#k" as well")。 "lsh x" / "rsh x" 原本就有保护,但 k > 31 的 "lsh #k" / "rsh #k" 会移位 超过 31 位,在 C 中是未定义行为,UBSan 报 "shift exponent 32 is too large for 32-bit type 'unsigned int'"。libpcap 自己生成的程序不会有 k > 31,但经 pcap_offline_filter() 传入的外部程序可以是任意值。该上游提交还会在 pcap_valid_insn() 中拒绝这类指令,而 pcap_valid_insn() 来自未回移的 commit 19718105,因此该 hunk 改写为 pcap_validate_filter() 中对应的位置。 Log: 回移漏掉的 BPF_JA 越界检查与 lsh/rsh "#k" 移位保护 Influence: 1. 构建 libpcap 并运行测试 2. 用大负偏移的 BPF_JMP|BPF_JA 调用 pcap_offline_filter(),确认拒绝报文 而不是崩溃 3. 编译使用移位的过滤器,确认仍能通过校验 4. 确认 pcap_validate_filter() 拒绝 "lsh #32"、接受 "lsh #31" 5. 确认补丁序列仍可被 quilt push -a 干净应用 repo: libpcap #fix-cve/CVE-2026-31911
|
/integrate |
CVE: CVE-2026-31911 (medium) - Fail opcodes safely in the BPF interpreter.
Upstream: https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9.patch
Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b
CVE: CVE-2026-18238 (medium) - Fix RPCAP_MSG_PACKET validation
Upstream: the-tcpdump-group/libpcap@b9590d4
Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b
CVE: CVE-2026-6244 (medium) - Avoid division by zero via pcap_offline_filter()
Upstream: the-tcpdump-group/libpcap@0b2b1ad
Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b
CVE: CVE-2026-31912 (medium) - Mind the program bounds in pcap_offline_filter()
Upstream: the-tcpdump-group/libpcap@d3f358d
Co-authored-by: hudeng hudeng@deepin.org
Generated-By: qwen3.6-35b