[PATCH net-next] vxlan: fix too large pskb_may_pull with remote checksum

Subsystems: networking drivers, the rest

STALE3834d

4 messages, 3 authors, 2016-03-19 · open the first message on its own page

[PATCH net-next] vxlan: fix too large pskb_may_pull with remote checksum

From: Jiri Benc <hidden>
Date: 2016-03-16 16:36:06

The vxlan header is pulled at this point, don't include it again in the
calculation.

Signed-off-by: Jiri Benc <redacted>
---
This was previously part of the VXLAN-GPE patchset but it's not really
related (especially not after the discussion that RCO should not be allowed
together with GPE). I'm sending it separately.
---
 drivers/net/vxlan.c | 6 ++----
 1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/drivers/net/vxlan.c b/drivers/net/vxlan.c
index 800106a7246c..1eb8347f440c 100644
--- a/drivers/net/vxlan.c
+++ b/drivers/net/vxlan.c
@@ -1143,7 +1143,7 @@ static int vxlan_igmp_leave(struct vxlan_dev *vxlan)
 static bool vxlan_remcsum(struct vxlanhdr *unparsed,
 			  struct sk_buff *skb, u32 vxflags)
 {
-	size_t start, offset, plen;
+	size_t start, offset;
 
 	if (!(unparsed->vx_flags & VXLAN_HF_RCO) || skb->remcsum_offload)
 		goto out;
@@ -1151,9 +1151,7 @@ static bool vxlan_remcsum(struct vxlanhdr *unparsed,
 	start = vxlan_rco_start(unparsed->vx_vni);
 	offset = start + vxlan_rco_offset(unparsed->vx_vni);
 
-	plen = sizeof(struct vxlanhdr) + offset + sizeof(u16);
-
-	if (!pskb_may_pull(skb, plen))
+	if (!pskb_may_pull(skb, offset + sizeof(u16)))
 		return false;
 
 	skb_remcsum_process(skb, (void *)(vxlan_hdr(skb) + 1), start, offset,
-- 
1.8.3.1

Re: [PATCH net-next] vxlan: fix too large pskb_may_pull with remote checksum

From: Tom Herbert <hidden>
Date: 2016-03-16 17:09:39

On Wed, Mar 16, 2016 at 9:35 AM, Jiri Benc [off-list ref] wrote:
The vxlan header is pulled at this point, don't include it again in the
calculation.
Hmm, I think I missing something obvious. Where was the pull of the
vxlan header done?

Thanks,
Tom
quoted hunk
Signed-off-by: Jiri Benc <redacted>
---
This was previously part of the VXLAN-GPE patchset but it's not really
related (especially not after the discussion that RCO should not be allowed
together with GPE). I'm sending it separately.
---
 drivers/net/vxlan.c | 6 ++----
 1 file changed, 2 insertions(+), 4 deletions(-)
diff --git a/drivers/net/vxlan.c b/drivers/net/vxlan.c
index 800106a7246c..1eb8347f440c 100644
--- a/drivers/net/vxlan.c
+++ b/drivers/net/vxlan.c
@@ -1143,7 +1143,7 @@ static int vxlan_igmp_leave(struct vxlan_dev *vxlan)
 static bool vxlan_remcsum(struct vxlanhdr *unparsed,
                          struct sk_buff *skb, u32 vxflags)
 {
-       size_t start, offset, plen;
+       size_t start, offset;

        if (!(unparsed->vx_flags & VXLAN_HF_RCO) || skb->remcsum_offload)
                goto out;
@@ -1151,9 +1151,7 @@ static bool vxlan_remcsum(struct vxlanhdr *unparsed,
        start = vxlan_rco_start(unparsed->vx_vni);
        offset = start + vxlan_rco_offset(unparsed->vx_vni);

-       plen = sizeof(struct vxlanhdr) + offset + sizeof(u16);
-
-       if (!pskb_may_pull(skb, plen))
+       if (!pskb_may_pull(skb, offset + sizeof(u16)))
                return false;

        skb_remcsum_process(skb, (void *)(vxlan_hdr(skb) + 1), start, offset,
--
1.8.3.1

Re: [PATCH net-next] vxlan: fix too large pskb_may_pull with remote checksum

From: Jiri Benc <hidden>
Date: 2016-03-16 17:13:32

On Wed, 16 Mar 2016 10:09:38 -0700, Tom Herbert wrote:
On Wed, Mar 16, 2016 at 9:35 AM, Jiri Benc [off-list ref] wrote:
quoted
The vxlan header is pulled at this point, don't include it again in the
calculation.
Hmm, I think I missing something obvious. Where was the pull of the
vxlan header done?
In iptunnel_pull_header. Sorry, should have mentioned it.

 Jiri

Re: [PATCH net-next] vxlan: fix too large pskb_may_pull with remote checksum

From: David Miller <davem@davemloft.net>
Date: 2016-03-19 02:19:54

From: Jiri Benc <redacted>
Date: Wed, 16 Mar 2016 17:35:47 +0100
The vxlan header is pulled at this point, don't include it again in the
calculation.

Signed-off-by: Jiri Benc <redacted>
Please update the commit log message to explain where that pull
happens.

Thanks.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help