> Good point, and probably an indication that my provider's setup is > broken. But in terms of RFC-perspective, RAs and ND are not strictly > related, I believe - for example, prefixes might have been configured > manually (?).
Hmm, I forgot one case: NBMA (Non-broadcast multiple-access). A prefix may be marked off-link though it is actually onlink. In that case all traffic initially goes through the router. Then the router will send a redirect with the target's MAC address. So the conclusion has to be that a node has accept NS packets with a source address that is off-link. > Exactly, that's where I couldn't understand the Advisory. Though > it seems to focus in router nodes, and not host nodes. Maybe some systems do not properly separate the neighbor cache from the destination cache. Junk in the neighbor cache should not affect the destination cache. So a node may be able to claim an address that is not onlink in the neighbor cache. But the destination cache should always have the right entry so the neighbor cache entry is ignored. I can imagine that if a system confuses the two then attacks are possible. _______________________________________________ freebsd-net@freebsd.org mailing list https://lists.freebsd.org/mailman/listinfo/freebsd-net To unsubscribe, send any mail to "freebsd-net-unsubscr...@freebsd.org"