Thread (6 messages) 6 messages, 3 authors, 5d ago

Re: [PATCH net v2] xfrm: validate ihl in xfrm4_transport_output()

From: Qihang <hidden>
Date: 2026-09-23 03:29:10
Also in: stable

On Wed, Sep 23, 2026 at 12:24:09PM +1000, Herbert Xu wrote:
As I said when this first came up, our entire IPv4 stack
assumes that this is validated upon entry into the IP stack.

So taking a whack-a-mole approach inside the IPv4 stack is the
wrong thing to do.

Please fix those entry points into the stack instead by ensuring
that the IP header is valid.
Understood, thanks.  v3 (posted as a new thread) drops the
xfrm4_transport_output() change and validates the header at the
xfrmi_xmit() entry instead, mirroring the pskb_inet_may_pull() call
that vti_tunnel_xmit() already has:

    [ref]

Thanks,
Qihang
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help