Thread (12 messages) 12 messages, 4 authors, 1d ago

Re: [PATCH net 5/5] vxlan: use pskb_network_may_pull() for transmit path header pulls

From: Vadim Fedorenko <vadim.fedorenko@linux.dev>
Date: 2026-07-23 16:44:06
Also in: stable

On 23/07/2026 15:42, Eric Dumazet wrote:
quoted hunk ↗ jump to hunk
In vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was
being called to verify the availability of network layer headers (ARP, IPv6/ND,
IP/IPv6 MDB keys).

However, during transmit skb->data points to the MAC header, so skb_network_offset(skb)
is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, len) only checks len bytes from skb->data
rather than skb_network_offset(skb) + len, which can leave part of the network header
in non-linear frags.

Replace these remaining pskb_may_pull() calls with pskb_network_may_pull() to properly
account for the MAC header offset.

Fixes: 465016142711 ("vxlan: Add ARP reduction support")
Fixes: 9e061a50a116 ("vxlan: Add IPv6 Neighbor Discovery reduction support")
Fixes: 4e94f09d84bf ("vxlan: add MDB support")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: stable@vger.kernel.org
---
  drivers/net/vxlan/vxlan_core.c | 6 +++---
  drivers/net/vxlan/vxlan_mdb.c  | 4 ++--
  2 files changed, 5 insertions(+), 5 deletions(-)
diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c
index 9ccbebda860480f8378918ff360deee1c46f3f7d..eff17987c5b531ecb1e2943b6274d20c1827d299 100644
--- a/drivers/net/vxlan/vxlan_core.c
+++ b/drivers/net/vxlan/vxlan_core.c
@@ -1850,7 +1850,7 @@ static int arp_reduce(struct net_device *dev, struct sk_buff *skb, __be32 vni)
  	if (dev->flags & IFF_NOARP)
  		goto out;
  
-	if (!pskb_may_pull(skb, arp_hdr_len(dev))) {
+	if (!pskb_network_may_pull(skb, arp_hdr_len(dev))) {
  		dev_dstats_tx_dropped(dev);
  		vxlan_vnifilter_count(vxlan, vni, NULL,
  				      VXLAN_VNI_STATS_TX_DROPS, 0);
@@ -2763,8 +2763,8 @@ static netdev_tx_t vxlan_xmit(struct sk_buff *skb, struct net_device *dev)
  			return arp_reduce(dev, skb, vni);
  #if IS_ENABLED(CONFIG_IPV6)
  		else if (ntohs(eth->h_proto) == ETH_P_IPV6 &&
-			 pskb_may_pull(skb, sizeof(struct ipv6hdr) +
-					    sizeof(struct nd_msg)) &&
+			 pskb_network_may_pull(skb, sizeof(struct ipv6hdr) +
+						    sizeof(struct nd_msg)) &&
  			 ipv6_hdr(skb)->nexthdr == IPPROTO_ICMPV6) {
  			struct nd_msg *m = (struct nd_msg *)(ipv6_hdr(skb) + 1);
  
diff --git a/drivers/net/vxlan/vxlan_mdb.c b/drivers/net/vxlan/vxlan_mdb.c
index af7a0d7f95a57a17486a8ecc277b7bb9d921a061..9a9038ae90c18c5f0e4362b2b254b0c48dfdad0e 100644
--- a/drivers/net/vxlan/vxlan_mdb.c
+++ b/drivers/net/vxlan/vxlan_mdb.c
@@ -1631,7 +1631,7 @@ struct vxlan_mdb_entry *vxlan_mdb_entry_skb_get(struct vxlan_dev *vxlan,
  
  	switch (skb->protocol) {
  	case htons(ETH_P_IP):
-		if (!pskb_may_pull(skb, sizeof(struct iphdr)))
+		if (!pskb_network_may_pull(skb, sizeof(struct iphdr)))
  			return NULL;
  		group.dst.sa.sa_family = AF_INET;
  		group.dst.sin.sin_addr.s_addr = ip_hdr(skb)->daddr;
@@ -1640,7 +1640,7 @@ struct vxlan_mdb_entry *vxlan_mdb_entry_skb_get(struct vxlan_dev *vxlan,
  		break;
  #if IS_ENABLED(CONFIG_IPV6)
  	case htons(ETH_P_IPV6):
-		if (!pskb_may_pull(skb, sizeof(struct ipv6hdr)))
+		if (!pskb_network_may_pull(skb, sizeof(struct ipv6hdr)))
  			return NULL;
  		group.dst.sa.sa_family = AF_INET6;
  		group.dst.sin6.sin6_addr = ipv6_hdr(skb)->daddr;
Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help