All of lore.kernel.org
 help / color / mirror / Atom feed
From: Ilya Maximets <i.maximets@ovn.org>
To: "Cen Zhang (Microsoft)" <blbllhy@gmail.com>,
	aconole@redhat.com, echaudro@redhat.com
Cc: netdev@vger.kernel.org, dev@openvswitch.org,
	linux-kernel@vger.kernel.org,
	AutonomousCodeSecurity@microsoft.com,
	tgopinath@linux.microsoft.com, kys@microsoft.com,
	i.maximets@ovn.org, davem@davemloft.net, pabeni@redhat.com,
	edumazet@google.com, kuba@kernel.org, horms@kernel.org
Subject: Re: [PATCH net v5] net/openvswitch: check Ethernet header length in key_extract()
Date: Fri, 31 Jul 2026 15:57:18 +0200	[thread overview]
Message-ID: <0ac6ed8a-aa9d-41f9-8a5d-cc7500a5f10d@ovn.org> (raw)
In-Reply-To: <20260730222006.118652-1-blbllhy@gmail.com>

On 7/31/26 12:20 AM, Cen Zhang (Microsoft) wrote:
> When a packet arrives on an ARPHRD_NONE device (e.g. TUN),
> ovs_flow_key_extract() trusts the user-provided skb->protocol field: if
> it is ETH_P_TEB, the packet is classified as MAC_PROTO_ETHERNET and
> key_extract() is called without ensuring the skb has ETH_HLEN (14) bytes
> of linear data. key_extract() unconditionally pulls 2 * ETH_ALEN bytes
> for MAC addresses and parse_ethertype() pulls 2 more, either of which
> triggers a kernel BUG in __skb_pull() when the linear area is too small.
> 
>   kernel BUG at include/linux/skbuff.h:2848!
>   RIP: 0010:key_extract+0xa7e/0xd90 net/openvswitch/flow.c:933
>   ovs_flow_key_extract+0x419/0xa70
>   ovs_vport_receive+0x222/0x390
>   netdev_frame_hook+0x3e0/0x630
>   tun_get_user+0x2d0c/0x38e0
> 
> Fixed by calling check_header() in key_extract() before accessing the
> Ethernet header.
> 
> Fixes: 217ac77a3c25 ("openvswitch: allow L3 netdev ports")
> Reported-by: AutonomousCodeSecurity@microsoft.com
> Reviewed-by: Eelco Chaudron <echaudro@redhat.com>
> Signed-off-by: Cen Zhang (Microsoft) <blbllhy@gmail.com>
> ---
> v5: Separate err declaration and initialization per review.
> v4: Update documentation and move variables into the Ethernet block.
> v3: Use check_header() per review, fix format issue.
> v2: Moved the check into key_extract() per Ilya Maximets.
> Link: https://lore.kernel.org/r/20260725043128.193164-1-blbllhy@gmail.com
Reviewed-by: Ilya Maximets <i.maximets@ovn.org>

      reply	other threads:[~2026-07-31 13:57 UTC|newest]

Thread overview: 2+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-30 22:20 [PATCH net v5] net/openvswitch: check Ethernet header length in key_extract() Cen Zhang (Microsoft)
2026-07-31 13:57 ` Ilya Maximets [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=0ac6ed8a-aa9d-41f9-8a5d-cc7500a5f10d@ovn.org \
    --to=i.maximets@ovn.org \
    --cc=AutonomousCodeSecurity@microsoft.com \
    --cc=aconole@redhat.com \
    --cc=blbllhy@gmail.com \
    --cc=davem@davemloft.net \
    --cc=dev@openvswitch.org \
    --cc=echaudro@redhat.com \
    --cc=edumazet@google.com \
    --cc=horms@kernel.org \
    --cc=kuba@kernel.org \
    --cc=kys@microsoft.com \
    --cc=linux-kernel@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    --cc=tgopinath@linux.microsoft.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.