mirror of
https://github.com/torvalds/linux.git
synced 2026-09-14 16:10:02 +02:00
tcf_pedit_act() computes the COW range for skb_ensure_writable()
once before the key loop using tcfp_off_max_hint, but the hint does
not account for the runtime header offset added by typed keys. This
can leave part of the write region un-COW'd.
Fix by moving skb_ensure_writable() inside the per-key loop where
the actual write offset is known, and add overflow checking on the
offset arithmetic. For negative offsets (e.g. Ethernet header edits
at ingress), use skb_cow() to COW the headroom instead. Guard
offset_valid() against INT_MIN, where negation is undefined.
Fixes:
|
||
|---|---|---|
| .. | ||
| tc_bpf.h | ||
| tc_connmark.h | ||
| tc_csum.h | ||
| tc_ct.h | ||
| tc_ctinfo.h | ||
| tc_defact.h | ||
| tc_gact.h | ||
| tc_gate.h | ||
| tc_ife.h | ||
| tc_mirred.h | ||
| tc_mpls.h | ||
| tc_nat.h | ||
| tc_pedit.h | ||
| tc_police.h | ||
| tc_sample.h | ||
| tc_skbedit.h | ||
| tc_skbmod.h | ||
| tc_tunnel_key.h | ||
| tc_vlan.h | ||