mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2026-09-22 09:34:56 +02:00
net: gro: properly validate BIG TCP aggregation criteria
When GRO attempts to aggregate packets beyond GRO_LEGACY_MAX_SIZE (64KB), BIG TCP should only be permitted for plain IPv4 TCP and plain IPv6 TCP (with sufficient MAC header room to insert the temporary HBH jumbo header). However, commitb1a78b9b98("net: add support for ipv4 big tcp") loosened the check in skb_gro_receive(), leading to several issues: 1. skb_gro_receive() checked skb_headroom(p) instead of the actual space before the MAC header (p->mac_header). Because skb_headroom(p) includes mac_len, crafted frames (e.g. injected via AF_PACKET) can pass the check with p->mac_header < 8 bytes. When ipv6_gro_complete() inserts the temporary HBH jumbo header, the memmove() starts before skb->head, causing an out-of-bounds write and wrapping skb->mac_header. 2. It allowed non-IP protocols such as software VLAN (ETH_P_8021Q / ETH_P_8021AD) to aggregate beyond 64KB because p->protocol != ETH_P_IPV6 was true. 3. It checked p->encapsulation instead of NAPI_GRO_CB(skb)->encap_mark, allowing encapsulated flows (e.g. SIT / IPv6-in-IPv4) to aggregate beyond 64KB. Fix skb_gro_receive() to strictly enforce: - NAPI_GRO_CB(skb)->proto == IPPROTO_TCP - Not encapsulated (!NAPI_GRO_CB(skb)->encap_mark && !p->encapsulation) - Protocol must be either ETH_P_IP or ETH_P_IPV6 - If ETH_P_IPV6, p->mac_header must be at least sizeof(struct hop_jumbo_hdr) Returning -E2BIG from skb_gro_receive() ensures that packets which cannot become BIG TCP are cleanly flushed at <= 64KB and delivered intact without dropping. This issue does not exist in mainline (7.0+) because the subsystem was rewritten in commit81be30c1f5("net/ipv6: Drop HBH for BIG TCP on RX side"), making this fix relevant only for older stable branches like 6.18.y. Fixes:0fe79f28bf("net: allow gro_max_size to exceed 65536") Fixes:b1a78b9b98("net: add support for ipv4 big tcp") Reported-by: Sam Dlinn <sledge@meta.com> Cc: stable@vger.kernel.org Signed-off-by: Eric Dumazet <edumazet@google.com> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
26741d178f
commit
e907bf694e
+5
-2
@@ -119,9 +119,12 @@ int skb_gro_receive(struct sk_buff *p, struct sk_buff *skb)
|
||||
|
||||
if (unlikely(p->len + len >= GRO_LEGACY_MAX_SIZE)) {
|
||||
if (NAPI_GRO_CB(skb)->proto != IPPROTO_TCP ||
|
||||
NAPI_GRO_CB(skb)->encap_mark ||
|
||||
p->encapsulation ||
|
||||
(p->protocol == htons(ETH_P_IPV6) &&
|
||||
skb_headroom(p) < sizeof(struct hop_jumbo_hdr)) ||
|
||||
p->encapsulation)
|
||||
p->mac_header < sizeof(struct hop_jumbo_hdr)) ||
|
||||
(p->protocol != htons(ETH_P_IPV6) &&
|
||||
p->protocol != htons(ETH_P_IP)))
|
||||
return -E2BIG;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user