Skip to content

[SECURITY] netfilter: nf_nat_proto_tcp: fix TCP UPDATE_SEQ handling (CVE-2016-9793)#134

Open
Mifacopy wants to merge 1 commit intofacebookincubator:oculus-go-kernel-masterfrom
Mifacopy:patch-31
Open

[SECURITY] netfilter: nf_nat_proto_tcp: fix TCP UPDATE_SEQ handling (CVE-2016-9793)#134
Mifacopy wants to merge 1 commit intofacebookincubator:oculus-go-kernel-masterfrom
Mifacopy:patch-31

Conversation

@Mifacopy
Copy link

Fix CVE-2016-9793.

Upstream commit: 6ef36ab967c71690ebe7e5ef997a8be4da3bc844

The nf_nat_proto_tcp module in netfilter performed unsafe handling of
TCP UPDATE_SEQ options, allowing crafted packets crossing a NAT boundary to
cause integer overflows or incorrect state adjustments. This could result
in denial of service (kernel panic) or malformed session state.

This patch tightens boundary checks and sequence adjustments in the
TCP update path to prevent invalid UPDATE_SEQ operations.

Reference: CVE-2016-9793

@meta-cla meta-cla bot added the CLA Signed Do not delete this pull request or issue due to inactivity. label Feb 14, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

CLA Signed Do not delete this pull request or issue due to inactivity.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant