linux/drivers/net/ppp
Qingfang Deng 8aaeb56aff ppp_synctty: ensure a writeable skb header
ppp_sync_txmunge() checks headroom before prepending the address and
control bytes, but does not ensure that the skb header is writable.
A received skb can reach this function through PPP channel bridging
without passing through ppp_start_xmit(), which calls skb_cow_head().

For example, a PPPoE frame may share its buffer with a clone queued to
an AF_PACKET socket. If it is bridged to a synchronous tty channel, the
address/control bytes can overwrite data still visible to that socket.

Use skb_cow_head() to ensure both sufficient headroom and a writable
header.

Fixes: 4cf476ced4 ("ppp: add PPPIOCBRIDGECHAN and PPPIOCUNBRIDGECHAN ioctls")
Signed-off-by: Qingfang Deng <qingfang.deng@linux.dev>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260908072135.877364-1-qingfang.deng@linux.dev
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
2026-09-09 18:41:57 -07:00
..
bsd_comp.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
Kconfig TTY / Serial driver update for 7.2-rc1 2026-06-22 11:51:49 -07:00
Makefile ppp: add PPPOX symbol 2026-04-28 18:31:10 -07:00
ppp_async.c ppp_async: drop the errored frame instead of resetting its headroom 2026-09-08 16:39:36 -07:00
ppp_deflate.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
ppp_generic.c ppp: annotate lockless queue empty check 2026-08-12 17:14:20 -07:00
ppp_mppe.c Convert 'alloc_obj' family to use the new default GFP_KERNEL argument 2026-02-21 17:09:51 -08:00
ppp_mppe.h
ppp_synctty.c ppp_synctty: ensure a writeable skb header 2026-09-09 18:41:57 -07:00
pppoe.c pppoe: remove redundant xmit wrapper 2026-08-05 18:34:20 -07:00
pppox.c pppox: drain queued packets on channel handoff 2026-08-17 14:00:30 -07:00
pptp.c pptp: drop packets received before connect 2026-08-12 17:17:53 -07:00