mirror of
https://github.com/torvalds/linux.git
synced 2026-09-11 20:13:02 +02:00
net/sched: fq_pie: clamp quantum in change path
fq_pie_change() accepts any quantum value from userspace, including 1.
With a crafted size table qdisc_pkt_len reaches ~2 GiB, so quantum=1
makes the deficit-refill loop spin ~2^31 times under the qdisc lock
(a soft lockup / denial of service).
Add max(256U, ...) matching fq_codel_change().
Conditions to recreate the bug:
CONFIG_NET_SCH_FQ_PIE=y. Requires CAP_NET_ADMIN (namespace-local via
unshare -Urn suffices).
tc qdisc add dev dummy0 root fq_pie
tc qdisc change dev dummy0 root fq_pie quantum 1 stab data 32768 size_log 15 cell_log 0
Fixes: ec97ecf1eb ("net: sched: add Flow Queue PIE packet scheduler")
Reported-by: Vega <vega@nebusec.ai>
Reviewed-by: Toke Høiland-Jørgensen <toke@redhat.com>
Tested-by: Victor Nogueira <victor@mojatatu.com>
Signed-off-by: Jamal Hadi Salim <jhs@mojatatu.com>
Link: https://patch.msgid.link/QDISC-0CFC.v3.20260901204856@mojatatu.com.3
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
094cc07f98
commit
4864f58c53
|
|
@ -341,7 +341,8 @@ static int fq_pie_change(struct Qdisc *sch, struct nlattr *opt,
|
|||
nla_get_u32(tb[TCA_FQ_PIE_BETA]));
|
||||
|
||||
if (tb[TCA_FQ_PIE_QUANTUM])
|
||||
WRITE_ONCE(q->quantum, nla_get_u32(tb[TCA_FQ_PIE_QUANTUM]));
|
||||
WRITE_ONCE(q->quantum,
|
||||
max(256U, nla_get_u32(tb[TCA_FQ_PIE_QUANTUM])));
|
||||
|
||||
if (tb[TCA_FQ_PIE_MEMORY_LIMIT])
|
||||
WRITE_ONCE(q->memory_limit,
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user