Thread (3 messages) flat view 3 messages, 3 authors, 27d ago

Re: [PATCH net v3] net: tun: bound receive headroom

From: patchwork-bot+netdevbpf@kernel.org
Date: 2026-08-14 03:24:38

Hello:

This patch was applied to netdev/net.git (main)
by Jakub Kicinski [off-list ref]:

On Wed, 12 Aug 2026 01:21:53 +0000 you wrote:
tun_get_user() uses tun->align both as skb headroom and when choosing how
much packet data to keep linear. OVS can propagate an oversized headroom
request from another port to TUN or TAP.

When align is larger than the usable space in a one-page skb head,
SKB_MAX_HEAD(align) underflows and the result becomes negative when stored
in good_linear. That value later wraps when assigned to the size_t linear
variable, and tun_alloc_skb() can place skb->data outside the allocated
head.

[...]
Here is the summary with links:
  - [net,v3] net: tun: bound receive headroom
    https://git.kernel.org/netdev/net/c/447c9303942c

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help