Thread (5 messages) 5 messages, 3 authors, 1d ago

Re: [PATCH net v1 2/2] i40e: validate TCP header before ATR access

From: Eric Dumazet <edumazet@kernel.org>
Date: 2026-09-27 13:59:27
Also in: intel-wired-lan

On Sat, Sep 26, 2026 at 8:23 PM Ren Wei [off-list ref] wrote:
quoted hunk ↗ jump to hunk
From: Zixuan Chai <redacted>

i40e_atr() uses ipv6_find_hdr() to locate the TCP header. A successful
protocol match does not verify that the complete TCP header is present in
the skb, so dereferencing the result can access data beyond the packet.

Check that the complete TCP header is available before inspecting it.

Fixes: fd0a05ce74ef ("i40e: transmit, receive, and NAPI")
Cc: stable@vger.kernel.org
Reported-by: Florian Westphal <fw@strlen.de>
Closes: https://lore.kernel.org/netfilter-devel/aq1HaYS96SNn7HJY@strlen.de/ (local)
Assisted-by: LLM
Signed-off-by: Zixuan Chai <redacted>
Signed-off-by: Ren Wei <redacted>
---
 drivers/net/ethernet/intel/i40e/i40e_txrx.c | 3 +++
 1 file changed, 3 insertions(+)
diff --git a/drivers/net/ethernet/intel/i40e/i40e_txrx.c b/drivers/net/ethernet/intel/i40e/i40e_txrx.c
index ef5e657816f0..cdac279b8aed 100644
--- a/drivers/net/ethernet/intel/i40e/i40e_txrx.c
+++ b/drivers/net/ethernet/intel/i40e/i40e_txrx.c
@@ -2911,6 +2911,9 @@ static void i40e_atr(struct i40e_ring *tx_ring, struct sk_buff *skb,

        if (l4_proto != IPPROTO_TCP)
                return;
+       if (unlikely(skb_tail_pointer(skb) < hdr.network + hlen +
+                            sizeof(struct tcphdr)))
+               return;

        th = (struct tcphdr *)(hdr.network + hlen);
pw-bot: cr

1) Please do not add bogus Reported-by: / Closes: tags. Florian never
reported an issue in i40e, unless this was not public?

2) How can this code be reached with a truncated or non-linear TCP header?
Unlike ixgbe_atr(), i40e_atr() returns immediately unless
tx_flags & (I40E_TX_FLAGS_IPV4 | I40E_TX_FLAGS_IPV6) is set.
Those flags are only set in i40e_tx_enable_csum(), which only acts on
CHECKSUM_PARTIAL packets and runs right before i40e_atr().

Furthermore, i40e_tx_enable_csum() (and i40e_tso()) already assumes the
network and transport headers are present in the linear skb head and
already dereferences ip.v4->version, ip.v6->nexthdr, and l4.tcp->doff
before i40e_atr() is ever called. Even within i40e_atr(), hdr.network
is already dereferenced prior to your check in the IPv4 branch.
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help