Thread (6 messages) 6 messages, 5 authors, 2025-11-05

Re: [PATCH net v7] virtio-net: fix received length check in big packets

From: patchwork-bot+netdevbpf@kernel.org
Date: 2025-11-05 03:00:32
Also in: lkml, stable, virtualization

Hello:

This patch was applied to netdev/net.git (main)
by Jakub Kicinski [off-list ref]:

On Thu, 30 Oct 2025 21:44:38 +0700 you wrote:
Since commit 4959aebba8c0 ("virtio-net: use mtu size as buffer length
for big packets"), when guest gso is off, the allocated size for big
packets is not MAX_SKB_FRAGS * PAGE_SIZE anymore but depends on
negotiated MTU. The number of allocated frags for big packets is stored
in vi->big_packets_num_skbfrags.

Because the host announced buffer length can be malicious (e.g. the host
vhost_net driver's get_rx_bufs is modified to announce incorrect
length), we need a check in virtio_net receive path. Currently, the
check is not adapted to the new change which can lead to NULL page
pointer dereference in the below while loop when receiving length that
is larger than the allocated one.

[...]
Here is the summary with links:
  - [net,v7] virtio-net: fix received length check in big packets
    https://git.kernel.org/netdev/net/c/0c716703965f

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help