Commit 78a4712
packet: use consistent hard_header_len in non-ring send paths
[ Upstream commit 03390aa ]
packet_snd() reads dev->hard_header_len multiple times while allocating
and constructing an skb. Device reconfiguration can change this value
concurrently, for example through bonding device type changes.
For SOCK_RAW, packet_snd() can save a larger value in reserve and later
allocate headroom using a smaller value. Moving skb->data back by reserve
then places it before skb->head, and the following copy from userspace can
attempt an out-of-bounds write.
packet_sendmsg_spkt() has the same issue because it calculates its
reservation and header offset from separate reads before dropping the RCU
read lock to allocate the skb.
Add LL_RESERVED_SPACE_EX() for callers that already saved a header length.
Read hard_header_len once in packet_snd() and use it for allocation and
construction. In packet_sendmsg_spkt(), preserve the allocation-time value
through the device lookup retry.
The separate SOCK_DGRAM consistency problem between hard_header_len and
header_ops->create is not addressed here.
Fixes: b84bbaf ("packet: in packet_snd start writing at link layer allocation")
Cc: stable@vger.kernel.org
Signed-off-by: Qihang Tang <q.h.hack.winter@gmail.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/20260805125729.19220-3-q.h.hack.winter@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Stable-dep-of: 21b5953 ("packet: use consistent hard_header_len in TX_RING send path")
Signed-off-by: Sasha Levin <sashal@kernel.org>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>1 parent 44bd0ec commit 78a4712
2 files changed
Lines changed: 20 additions & 12 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
274 | 274 | | |
275 | 275 | | |
276 | 276 | | |
277 | | - | |
278 | | - | |
| 277 | + | |
| 278 | + | |
279 | 279 | | |
| 280 | + | |
| 281 | + | |
280 | 282 | | |
281 | 283 | | |
282 | 284 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1972 | 1972 | | |
1973 | 1973 | | |
1974 | 1974 | | |
1975 | | - | |
| 1975 | + | |
1976 | 1976 | | |
| 1977 | + | |
1977 | 1978 | | |
1978 | 1979 | | |
1979 | 1980 | | |
| |||
2016 | 2017 | | |
2017 | 2018 | | |
2018 | 2019 | | |
| 2020 | + | |
| 2021 | + | |
| 2022 | + | |
| 2023 | + | |
2019 | 2024 | | |
2020 | | - | |
| 2025 | + | |
2021 | 2026 | | |
2022 | 2027 | | |
2023 | 2028 | | |
2024 | | - | |
| 2029 | + | |
2025 | 2030 | | |
2026 | | - | |
| 2031 | + | |
2027 | 2032 | | |
2028 | 2033 | | |
2029 | 2034 | | |
| |||
2053 | 2058 | | |
2054 | 2059 | | |
2055 | 2060 | | |
2056 | | - | |
| 2061 | + | |
2057 | 2062 | | |
2058 | 2063 | | |
2059 | 2064 | | |
| |||
2969 | 2974 | | |
2970 | 2975 | | |
2971 | 2976 | | |
2972 | | - | |
| 2977 | + | |
2973 | 2978 | | |
2974 | 2979 | | |
2975 | 2980 | | |
| |||
3010 | 3015 | | |
3011 | 3016 | | |
3012 | 3017 | | |
| 3018 | + | |
3013 | 3019 | | |
3014 | | - | |
| 3020 | + | |
3015 | 3021 | | |
3016 | 3022 | | |
3017 | 3023 | | |
| |||
3033 | 3039 | | |
3034 | 3040 | | |
3035 | 3041 | | |
3036 | | - | |
| 3042 | + | |
3037 | 3043 | | |
3038 | 3044 | | |
3039 | | - | |
| 3045 | + | |
3040 | 3046 | | |
3041 | 3047 | | |
3042 | 3048 | | |
| |||
3052 | 3058 | | |
3053 | 3059 | | |
3054 | 3060 | | |
3055 | | - | |
| 3061 | + | |
3056 | 3062 | | |
3057 | 3063 | | |
3058 | 3064 | | |
| |||
0 commit comments