From: Jason Wang <hidden> Date: 2015-08-04 09:55:53
virtio declares support for NETIF_F_FRAGLIST, but assumes
that there are at most MAX_SKB_FRAGS + 2 fragments which isn't
always true with a fraglist.
A longer fraglist in the skb will make the call to skb_to_sgvec overflow
the sg array, leading to memory corruption.
Drop NETIF_F_FRAGLIST so we only get what we can handle.
Cc: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Jason Wang <redacted>
---
The patch is needed for stable.
---
drivers/net/virtio_net.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
@@ -1756,9 +1756,9 @@ static int virtnet_probe(struct virtio_device *vdev)/* Do we support "hardware" checksums? */if(virtio_has_feature(vdev,VIRTIO_NET_F_CSUM)){/* This opens up the world of extra features. */-dev->hw_features|=NETIF_F_HW_CSUM|NETIF_F_SG|NETIF_F_FRAGLIST;+dev->hw_features|=NETIF_F_HW_CSUM|NETIF_F_SG;if(csum)-dev->features|=NETIF_F_HW_CSUM|NETIF_F_SG|NETIF_F_FRAGLIST;+dev->features|=NETIF_F_HW_CSUM|NETIF_F_SG;if(virtio_has_feature(vdev,VIRTIO_NET_F_GSO)){dev->hw_features|=NETIF_F_TSO|NETIF_F_UFO
From: "Michael S. Tsirkin" <mst@redhat.com> Date: 2015-08-04 10:05:39
On Tue, Aug 04, 2015 at 05:55:45PM +0800, Jason Wang wrote:
virtio declares support for NETIF_F_FRAGLIST, but assumes
that there are at most MAX_SKB_FRAGS + 2 fragments which isn't
always true with a fraglist.
A longer fraglist in the skb will make the call to skb_to_sgvec overflow
the sg array, leading to memory corruption.
Drop NETIF_F_FRAGLIST so we only get what we can handle.
Cc: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Jason Wang <redacted>
Acked-by: Michael S. Tsirkin <mst@redhat.com>
Especially important now that virtio_net: add gro capability
was merged for net-next, making bridged setups create fraglists.
quoted hunk
---
The patch is needed for stable.
---
drivers/net/virtio_net.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
@@ -1756,9 +1756,9 @@ static int virtnet_probe(struct virtio_device *vdev)/* Do we support "hardware" checksums? */if(virtio_has_feature(vdev,VIRTIO_NET_F_CSUM)){/* This opens up the world of extra features. */-dev->hw_features|=NETIF_F_HW_CSUM|NETIF_F_SG|NETIF_F_FRAGLIST;+dev->hw_features|=NETIF_F_HW_CSUM|NETIF_F_SG;if(csum)-dev->features|=NETIF_F_HW_CSUM|NETIF_F_SG|NETIF_F_FRAGLIST;+dev->features|=NETIF_F_HW_CSUM|NETIF_F_SG;if(virtio_has_feature(vdev,VIRTIO_NET_F_GSO)){dev->hw_features|=NETIF_F_TSO|NETIF_F_UFO
From: Sergei Shtylyov <hidden> Date: 2015-08-04 11:11:05
Hello.
On 8/4/2015 12:55 PM, Jason Wang wrote:
virtio declares support for NETIF_F_FRAGLIST, but assumes
that there are at most MAX_SKB_FRAGS + 2 fragments which isn't
always true with a fraglist.
A longer fraglist in the skb will make the call to skb_to_sgvec overflow
the sg array, leading to memory corruption.
Drop NETIF_F_FRAGLIST so we only get what we can handle.
Cc: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Jason Wang <redacted>
---
The patch is needed for stable.
---
drivers/net/virtio_net.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
@@ -1756,9 +1756,9 @@ static int virtnet_probe(struct virtio_device *vdev)/* Do we support "hardware" checksums? */if(virtio_has_feature(vdev,VIRTIO_NET_F_CSUM)){/* This opens up the world of extra features. */-dev->hw_features|=NETIF_F_HW_CSUM|NETIF_F_SG|NETIF_F_FRAGLIST;+dev->hw_features|=NETIF_F_HW_CSUM|NETIF_F_SG;if(csum)-dev->features|=NETIF_F_HW_CSUM|NETIF_F_SG|NETIF_F_FRAGLIST;+dev->features|=NETIF_F_HW_CSUM|NETIF_F_SG;
I'd have added spaces around | to match the style seen below.
if (virtio_has_feature(vdev, VIRTIO_NET_F_GSO)) {
dev->hw_features |= NETIF_F_TSO | NETIF_F_UFO
From: Jason Wang <hidden> Date: 2015-08-05 02:32:10
On 08/04/2015 07:11 PM, Sergei Shtylyov wrote:
Hello.
On 8/4/2015 12:55 PM, Jason Wang wrote:
quoted
virtio declares support for NETIF_F_FRAGLIST, but assumes
that there are at most MAX_SKB_FRAGS + 2 fragments which isn't
always true with a fraglist.
quoted
A longer fraglist in the skb will make the call to skb_to_sgvec overflow
the sg array, leading to memory corruption.
quoted
Drop NETIF_F_FRAGLIST so we only get what we can handle.
quoted
Cc: Michael S. Tsirkin <mst@redhat.com>
Signed-off-by: Jason Wang <redacted>
---
The patch is needed for stable.
---
drivers/net/virtio_net.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
@@ -1756,9 +1756,9 @@ static int virtnet_probe(struct virtio_device
*vdev)
/* Do we support "hardware" checksums? */
if (virtio_has_feature(vdev, VIRTIO_NET_F_CSUM)) {
/* This opens up the world of extra features. */
- dev->hw_features |=
NETIF_F_HW_CSUM|NETIF_F_SG|NETIF_F_FRAGLIST;
+ dev->hw_features |= NETIF_F_HW_CSUM|NETIF_F_SG;
if (csum)
- dev->features |=
NETIF_F_HW_CSUM|NETIF_F_SG|NETIF_F_FRAGLIST;
+ dev->features |= NETIF_F_HW_CSUM|NETIF_F_SG;
I'd have added spaces around | to match the style seen below.
Ok, will fix this in V2.
quoted
if (virtio_has_feature(vdev, VIRTIO_NET_F_GSO)) {
dev->hw_features |= NETIF_F_TSO | NETIF_F_UFO