Thread (4 messages) flat view 4 messages, 3 authors, 19d ago

Re: [PATCH net v2] net: iptunnel: fix stale transport header during tunnel decapsulation

From: Eric Dumazet <edumazet@google.com>
Date: 2026-08-25 10:00:06

On Tue, Aug 25, 2026 at 11:41 AM Dong Chenchen [off-list ref] wrote:
quoted hunk ↗ jump to hunk
Syzbot reported a crash in qdisc_pkt_len_segs_init() caused by a stale
transport_header offset after tunnel decapsulation.


The issue is completely latent until qdisc read transport header in
commit 7fb4c1967011 ("net: pull headers in qdisc_pkt_len_segs_init()").
The crash requires four conditions to line up:

1. The incoming packet is encapsulated and carries GSO metadata. The outer
   transport header offset is stored in skb->transport_header while the
   packet is still in the outer tunnel context.
2. The tunnel receiver strips the outer headers. skb->data is advanced to
   the inner frame, but skb->transport_header is left pointing to the
   now-removed outer L4 header, so it becomes a negative offset relative to
   the new data.
3. The inner frame is not delivered to the local IP stack. Instead, it
   is forwarded at L2 by a bridge or HSR, so ip_rcv_core() never runs and
   the transport header is not reset to the inner L4 offset.
4. The forwarding path calls __dev_queue_xmit(), which enters
   qdisc_pkt_len_segs_init(). That function computes the GSO header length
   from skb_transport_offset(skb). Because the offset is negative, the
   unsigned cast overflows and pskb_may_pull(skb, hdr_len +
   sizeof(struct tcphdr)) reads past the end of the skb, triggering a
   KASAN fault or page fault.

The issue specifically requires GSO packets (shinfo->gso_size != 0), which
are processed/aggregated through gro_cells. Fix this by clearing
transport_header to the ~0U sentinel in gro_cell for all tunnnel driver.
GTP does not support GRO/GSO, drop the evil GSO packets in GTP directly.

Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Reported-by: syzbot+83181a31faf9455499c5@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/all/69de2bee.a00a0220.475f0.0041.GAE@google.com/T/ (local)
Suggested-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Dong Chenchen <redacted>
---
 drivers/net/gtp.c      | 5 +++++
 include/linux/skbuff.h | 5 +++++
 net/core/gro_cells.c   | 2 ++
 3 files changed, 12 insertions(+)
diff --git a/drivers/net/gtp.c b/drivers/net/gtp.c
index 9a12cc53da00..fbf617b1acc9 100644
--- a/drivers/net/gtp.c
+++ b/drivers/net/gtp.c
@@ -312,6 +312,11 @@ static int gtp_inner_proto(struct sk_buff *skb, unsigned int hdrlen,
 static int gtp_rx(struct pdp_ctx *pctx, struct sk_buff *skb,
                  unsigned int hdrlen, unsigned int role, __u16 inner_proto)
 {
+       if (skb_is_gso(skb)) {
+               netdev_dbg(pctx->dev, "GSO is not support in GTP\n");
Patch looks good to me but there is a small typo here.

                    netdev_dbg(pctx->dev, "GSO is not supported in GTP\n");

Reviewed-by: Eric Dumazet <edumazet@google.com>

Thanks.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help