mirror of
https://github.com/torvalds/linux.git
synced 2026-09-22 04:34:03 +02:00
xdp: reject clones that overrun skb_shared_info tailroom
xdpf_clone() clones broadcast copies into a single page and sets
frame_sz to PAGE_SIZE. __xdp_build_skb_from_frame() later treats that
page like a normal XDP frame and expects the usual skb_shared_info
tailroom at the end of the buffer.
The current check only rejects frames whose linear xdp_frame header,
headroom, and packet data exceed PAGE_SIZE. A source frame backed by a
larger allocation can still satisfy that check while extending into the
clone's required shared-info area. When such a clone is converted back
into an skb, build_skb_around() places skb_shared_info over live packet
bytes and later writes can corrupt XDP return metadata.
Reject clones unless their linear area fits inside
SKB_WITH_OVERHEAD(PAGE_SIZE), matching the tailroom requirement already
enforced by the XDP-to-skb conversion path.
Fixes: e624d4ed4a ("xdp: Extend xdp_redirect_map with broadcast support")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Link: https://patch.msgid.link/6b2afef5d1738763c6965e8e466eb16e43e4f956.1785757386.git.zhilinz@nebusec.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
c53900b3f1
commit
e48e8edbef
|
|
@ -871,7 +871,7 @@ struct xdp_frame *xdpf_clone(struct xdp_frame *xdpf)
|
|||
headroom = xdpf->headroom + sizeof(*xdpf);
|
||||
totalsize = headroom + xdpf->len;
|
||||
|
||||
if (unlikely(totalsize > PAGE_SIZE))
|
||||
if (unlikely(totalsize > SKB_WITH_OVERHEAD(PAGE_SIZE)))
|
||||
return NULL;
|
||||
page = dev_alloc_page();
|
||||
if (!page)
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user