Thread (5 messages) 5 messages, 3 authors, 2d ago
WARM2d

[PATCH net v1 2/2] i40e: validate TCP header before ATR access

From: Ren Wei <hidden>
Date: 2026-09-26 18:23:42
Also in: intel-wired-lan
Subsystem: intel ethernet drivers, networking drivers, the rest · Maintainers: Tony Nguyen, Przemek Kitszel, Andrew Lunn, "David S. Miller", Eric Dumazet, Jakub Kicinski, Paolo Abeni, Linus Torvalds

From: Zixuan Chai <redacted>

i40e_atr() uses ipv6_find_hdr() to locate the TCP header. A successful
protocol match does not verify that the complete TCP header is present in
the skb, so dereferencing the result can access data beyond the packet.

Check that the complete TCP header is available before inspecting it.

Fixes: fd0a05ce74ef ("i40e: transmit, receive, and NAPI")
Cc: stable@vger.kernel.org
Reported-by: Florian Westphal <fw@strlen.de>
Closes: https://lore.kernel.org/netfilter-devel/aq1HaYS96SNn7HJY@strlen.de/ (local)
Assisted-by: LLM
Signed-off-by: Zixuan Chai <redacted>
Signed-off-by: Ren Wei <redacted>
---
 drivers/net/ethernet/intel/i40e/i40e_txrx.c | 3 +++
 1 file changed, 3 insertions(+)
diff --git a/drivers/net/ethernet/intel/i40e/i40e_txrx.c b/drivers/net/ethernet/intel/i40e/i40e_txrx.c
index ef5e657816f0..cdac279b8aed 100644
--- a/drivers/net/ethernet/intel/i40e/i40e_txrx.c
+++ b/drivers/net/ethernet/intel/i40e/i40e_txrx.c
@@ -2911,6 +2911,9 @@ static void i40e_atr(struct i40e_ring *tx_ring, struct sk_buff *skb,
 
 	if (l4_proto != IPPROTO_TCP)
 		return;
+	if (unlikely(skb_tail_pointer(skb) < hdr.network + hlen +
+			     sizeof(struct tcphdr)))
+		return;
 
 	th = (struct tcphdr *)(hdr.network + hlen);
 
-- 
2.34.1
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help