mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 09:36:22 +02:00
net: mana: Validate the packet length reported by the NIC
Validate the packet length reported in the RX CQE before passing it
to skb processing. The CQE is supplied by the NIC device and should
not be blindly trusted.
Cc: stable@vger.kernel.org
Reviewed-by: Haiyang Zhang <haiyangz@microsoft.com>
Signed-off-by: Dexuan Cui <decui@microsoft.com>
Fixes: ca9c54d2d6 ("net: mana: Add a driver for Microsoft Azure Network Adapter (MANA)")
Link: https://patch.msgid.link/20260702041237.617719-2-decui@microsoft.com
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
This commit is contained in:
parent
f4ef35efbb
commit
2e2a83b499
|
|
@ -2246,12 +2246,25 @@ static void mana_process_rx_cqe(struct mana_rxq *rxq, struct mana_cq *cq,
|
|||
rxbuf_oob = &rxq->rx_oobs[curr];
|
||||
WARN_ON_ONCE(rxbuf_oob->wqe_inf.wqe_size_in_bu != 1);
|
||||
|
||||
mana_refill_rx_oob(dev, rxq, rxbuf_oob, &old_buf, &old_fp);
|
||||
if (unlikely(pktlen > rxq->datasize)) {
|
||||
/* Increase it even if mana_rx_skb() isn't called. */
|
||||
rxq->rx_cq.work_done++;
|
||||
|
||||
/* Unsuccessful refill will have old_buf == NULL.
|
||||
* In this case, mana_rx_skb() will drop the packet.
|
||||
*/
|
||||
mana_rx_skb(old_buf, old_fp, oob, rxq, i);
|
||||
++ndev->stats.rx_dropped;
|
||||
netdev_warn_once(ndev,
|
||||
"Dropped oversized RX packet: len=%u, datasize=%u\n",
|
||||
pktlen, rxq->datasize);
|
||||
|
||||
/* Reuse the RX buffer since rxbuf_oob is unchanged. */
|
||||
} else {
|
||||
|
||||
mana_refill_rx_oob(dev, rxq, rxbuf_oob, &old_buf, &old_fp);
|
||||
|
||||
/* Unsuccessful refill will have old_buf == NULL.
|
||||
* In this case, mana_rx_skb() will drop the packet.
|
||||
*/
|
||||
mana_rx_skb(old_buf, old_fp, oob, rxq, i);
|
||||
}
|
||||
|
||||
mana_move_wq_tail(rxq->gdma_rq,
|
||||
rxbuf_oob->wqe_inf.wqe_size_in_bu);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user