mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-09-22 09:34:56 +02:00
net/sched: cake: reject overhead values that underflow length
[ Upstream commitb7f97cae7e] CAKE accepts signed overhead values and stores them in an s16, but the adjusted packet length calculation uses unsigned arithmetic. A negative effective length can therefore wrap to a large value. Such configurations make rate accounting depend on integer wraparound rather than on the packet size userspace intended to model. A static netlink lower bound is not enough because packets reaching CAKE can be smaller than any reasonable manual-overhead allowance. Fold the signed overhead adjustment into the existing datapath MPU clamp so negative adjusted lengths are clamped before link-layer framing adjustments. Fixes:a729b7f0bd("sch_cake: Add overhead compensation support to the rate shaper") Assisted-by: Codex:gpt-5.5-cyber-preview Signed-off-by: Samuel Moelius <sam.moelius@trailofbits.com> Acked-by: Toke Høiland-Jørgensen <toke@toke.dk> Link: https://patch.msgid.link/20260702000758.297407.e5c888d9d99d.cake-overhead-underflow@trailofbits.com Signed-off-by: Paolo Abeni <pabeni@redhat.com> Signed-off-by: Sasha Levin <sashal@kernel.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
ff431529d3
commit
336c1e414f
@@ -1382,10 +1382,7 @@ static u32 cake_calc_overhead(struct cake_sched_data *q, u32 len, u32 off)
|
||||
if (q->min_netlen > len)
|
||||
q->min_netlen = len;
|
||||
|
||||
len += q->rate_overhead;
|
||||
|
||||
if (len < q->rate_mpu)
|
||||
len = q->rate_mpu;
|
||||
len = max((s32)len + q->rate_overhead, (s32)q->rate_mpu);
|
||||
|
||||
if (q->atm_mode == CAKE_ATM_ATM) {
|
||||
len += 47;
|
||||
|
||||
Reference in New Issue
Block a user