All of lore.kernel.org
 help / color / mirror / Atom feed
From: patchwork-bot+netdevbpf@kernel.org
To: manizada <manizada@pm.me>
Cc: netdev@vger.kernel.org, andrew+netdev@lunn.ch,
	davem@davemloft.net, edumazet@google.com, kuba@kernel.org,
	pabeni@redhat.com, linux-kernel@vger.kernel.org
Subject: Re: [PATCH net] pppoe: reload header pointer after dev_hard_header()
Date: Thu, 23 Jul 2026 14:10:20 +0000	[thread overview]
Message-ID: <178481582039.2248593.12234026295292829000.git-patchwork-notify@kernel.org> (raw)
In-Reply-To: <20260722093814.3017176-1-manizada@pm.me>

Hello:

This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@kernel.org>:

On Wed, 22 Jul 2026 09:38:43 +0000 you wrote:
> pppoe_sendmsg() saves a pointer to the PPPoE header before calling
> dev_hard_header(). Device header callbacks are allowed to reallocate the
> skb head, invalidating pointers into it.
> 
> This can happen when a send is blocked in copy_from_user() while the first
> non-Ethernet port is added to an empty team device. The team's delegated
> GRE header callback then expands the skb head. PPPoE subsequently writes
> six bytes through the stale pointer into the freed head.
> 
> [...]

Here is the summary with links:
  - [net] pppoe: reload header pointer after dev_hard_header()
    https://git.kernel.org/netdev/net/c/e9c238f6fe42

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



      parent reply	other threads:[~2026-07-23 14:10 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-22  9:38 [PATCH net] pppoe: reload header pointer after dev_hard_header() Asim Viladi Oglu Manizada
2026-07-22 11:17 ` Vadim Fedorenko
2026-07-22 12:31   ` Eric Dumazet
2026-07-23 14:10 ` patchwork-bot+netdevbpf [this message]

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=178481582039.2248593.12234026295292829000.git-patchwork-notify@kernel.org \
    --to=patchwork-bot+netdevbpf@kernel.org \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=manizada@pm.me \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.