aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorMark Johnston <markj@FreeBSD.org>2026-09-21 14:05:01 +0000
committerMark Johnston <markj@FreeBSD.org>2026-09-28 18:14:41 +0000
commitae084d5f1d7cce37d89aeda30fb27f28d46e2038 (patch)
tree04543e400dc66b9591f2ca0db42f23f009e604f7
parentaf45dd667d44abbe01a31da9aec894419cafbf9b (diff)
udp: Let jail policy rewrite the dstaddr for v6 sendto()s
When performing an unconnected sendto() on a v6 UDP socket in a classic jail, we were not applying the usual policy of replacing the loopback addr with the jail's primary IP. Compare with, e.g., udp6_connect() or the IPv4 udp_send(). Fix that. Approved by: so Security: FreeBSD-SA-26:69.udp Security: CVE-2026-101303 Reported by: Yuxiang Yang, Yizhou Zhao, Ao Wang, Xuewei Feng, Qi Li, and Ke Xu from Tsinghua University using GLM-5.1 from Z.ai Reviewed by: bz, glebius MFC after: 2 weeks Sponsored by: The FreeBSD Foundation Differential Revision: https://reviews.freebsd.org/D59772 (cherry picked from commit fecb9537a83b6746bc731a7cb3bcf6a33df79562) (cherry picked from commit f3b4b6b756e2ce9e012068c5c91492f757b5c548)
-rw-r--r--sys/netinet6/udp6_usrreq.c4
1 files changed, 4 insertions, 0 deletions
diff --git a/sys/netinet6/udp6_usrreq.c b/sys/netinet6/udp6_usrreq.c
index 1a32365f5d1d..2feb35442f7e 100644
--- a/sys/netinet6/udp6_usrreq.c
+++ b/sys/netinet6/udp6_usrreq.c
@@ -831,6 +831,10 @@ udp6_send(struct socket *so, int flags_arg, struct mbuf *m,
("%s: sin6(%p)->sin6_addr is v4mapped which we "
"should have handled.", __func__, sin6));
+ error = prison_remote_ip6(td->td_ucred, &sin6->sin6_addr);
+ if (error != 0)
+ goto release;
+
/* This only requires read-locking. */
error = in6_selectsrc_socket(sin6, optp, inp,
td->td_ucred, scope_ambiguous, &in6a, NULL);