Thread (10 messages) 10 messages, 4 authors, 2026-01-31

Re: [PATCH net 0/2] gve: fix crashes on invalid TX queue indices

From: Jakub Kicinski <kuba@kernel.org>
Date: 2026-01-08 16:31:33
Also in: lkml, stable

On Thu, 8 Jan 2026 07:35:59 -0800 Ankit Garg wrote:
On Tue, Jan 6, 2026 at 6:22 PM Jakub Kicinski [off-list ref] wrote:
quoted
On Mon,  5 Jan 2026 15:25:02 -0800 Joshua Washington wrote:  
quoted
This series fixes a kernel panic in the GVE driver caused by
out-of-bounds array access when the network stack provides an invalid
TX queue index.  
Do you know how? I seem to recall we had such issues due to bugs
in the qdisc layer, most of which were fixed.

Fixing this at the source, if possible, would be far preferable
to sprinkling this condition to all the drivers.  
That matches our observation—we have encountered this panic on older
kernels (specifically Rocky Linux 8) but have not been able to
reproduce it on recent upstream kernels.

Could you point us to the specific qdisc fixes you recall? We'd like
to verify if the issue we are seeing on the older kernel is indeed one
of those known/fixed bugs.
Very old - ac5b70198adc25
If it turns out this is fully resolved in the core network stack
upstream, we can drop this patch for the mainline driver. However, if
there is ambiguity, do you think there is value in keeping this check
to prevent the driver from crashing on invalid input?
The API contract is that the stack does not send frames for queues
which don't exist (> real_num_tx_queues) down to the drivers.
There's no ambiguity, IMO, if the stack sends such frames its a bug
in the stack.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help