mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 17:47:41 +02:00
batman-adv: retrieve ethhdr after potential skb realloc on RX
pskb_may_pull() in batadv_interface_rx() could reallocate the buffer behind the skb. Variables which were pointing to the old buffer need to be reassigned to avoid an use-after-free. This was done correctly for the VLAN header but missed for the ethernet header which is later used for the TT and AP isolation handling. Cc: stable@vger.kernel.org Reported-by: Sashiko <sashiko-bot@kernel.org> Fixes:c6c8fea297("net: Add batman-adv meshing protocol") Fixes:c78296665c("batman-adv: Check skb size before using encapsulated ETH+VLAN header") Signed-off-by: Sven Eckelmann <sven@narfation.org>
This commit is contained in:
parent
805185b7c7
commit
035e1fed89
|
|
@ -434,6 +434,7 @@ void batadv_interface_rx(struct net_device *mesh_iface,
|
|||
if (!pskb_may_pull(skb, VLAN_ETH_HLEN))
|
||||
goto dropped;
|
||||
|
||||
ethhdr = eth_hdr(skb);
|
||||
vhdr = skb_vlan_eth_hdr(skb);
|
||||
|
||||
/* drop batman-in-batman packets to prevent loops */
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user