Thread (2 messages) 2 messages, 2 authors, 8d ago

Re: [PATCH] bpf: reject unset network_header for SKF_NET_OFF in cBPF load helper

From: Alexei Starovoitov <hidden>
Date: 2026-09-19 23:18:28
Also in: bpf, lkml

On Sat, Sep 19, 2026 at 08:35 PM Hui Peng [off-list ref] wrote:
quoted hunk ↗ jump to hunk
diff --git a/net/core/filter.c b/net/core/filter.c
--- a/net/core/filter.c
+++ b/net/core/filter.c
@@ -231,8 +231,14 @@ static int bpf_skb_load_helper_convert_offset(const struct sk_buff *skb, int off
 	if (likely(offset >= 0))
 		return offset;

-	if (offset >= SKF_NET_OFF)
+	if (offset >= SKF_NET_OFF) {
+		if (skb_mac_header_was_set(skb) ?
+		    skb->network_header < skb->mac_header :
+		    (skb_network_offset(skb) < 0 ||
+		     (!skb->protocol && !skb->network_header)))
+			return INT_MIN;
No. network_header == 0 is a valid value when there is no headroom and
skb->protocol says nothing about it.

When netlink_dump() had this problem it was fixed by
skb_reset_network_header() after skb_reserve(). See
commit 99c07327ae11 ("netlink: reset network and mac headers in netlink_dump()").

pw-bot: cr
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help