Skip to content

inet6: fix IndexError when dissecting IPv6 with truncated nh=43 payload - #5214

Open
jimi18102010-commits wants to merge 1 commit into
secdev:masterfrom
jimi18102010-commits:fix-ipv6-nh43-indexerror
Open

jimi18102010-commits wants to merge 1 commit into
secdev:masterfrom
jimi18102010-commits:fix-ipv6-nh43-indexerror

Conversation

@jimi18102010-commits

Copy link
Copy Markdown
Contributor

Reopens #5207 (reverted in #5210).

When self.nh == 43, default_payload_class accessed p[2] without verifying len(p) > 2, causing an IndexError for payloads shorter than 3 bytes.

Tests on master are now passing, and the commit includes the required AI-Assisted trailer.

Closes #5206

@codecov

codecov Bot commented Oct 1, 2026 •

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 81.14%. Comparing base (9ef9871) to head (ded9b19).

Additional details and impacted files
@@            Coverage Diff             @@
##           master    #5214      +/-   ##
==========================================
- Coverage   81.14%   81.14%   -0.01%     
==========================================
  Files         393      393              
  Lines       98316    98316              
==========================================
- Hits        79783    79776       -7     
- Misses      18533    18540       +7     
Files with missing lines Coverage Δ
scapy/layers/inet6.py 88.79% <100.00%> (ø)

... and 8 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

When self.nh == 43, default_payload_class accessed p[2] without
verifying that len(p) > 2, causing an IndexError for payloads
shorter than 3 bytes. Add length check and regression test.

Closes secdev#5206
Reopens secdev#5207

AI-Assisted: no
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

IPv6 dissection raises IndexError when nh=43 and payload is shorter than 3 bytes

1 participant