All of lore.kernel.org
 help / color / mirror / Atom feed
* Patch "tunnels: Don't apply GRO to multiple layers of encapsulation" (CVE-2016-8666) is missing in 4.1 and 3.18 stable tree
@ 2017-01-10  2:09 Thomas Deutschmann
  2017-01-10  6:45 ` Greg KH
  0 siblings, 1 reply; 4+ messages in thread
From: Thomas Deutschmann @ 2017-01-10  2:09 UTC (permalink / raw)
  To: stable@vger.kernel.org; +Cc: jesse, davem@davemloft.net, alexander.levin


[-- Attachment #1.1: Type: text/plain, Size: 1388 bytes --]

Hi,

the following patch was backported to the following LTS kernels

- >=4.4.29
- >=3.16.35


however it is missing from LTS kernels

- linux-4.1
- linux-3.18


> From fac8e0f579695a3ecbc4d3cac369139d7f819971 Mon Sep 17 00:00:00 2001
> From: Jesse Gross <jesse@kernel.org>
> Date: Sat, 19 Mar 2016 09:32:01 -0700
> Subject: [PATCH] tunnels: Don't apply GRO to multiple layers of encapsulation.
> 
> When drivers express support for TSO of encapsulated packets, they
> only mean that they can do it for one layer of encapsulation.
> Supporting additional levels would mean updating, at a minimum,
> more IP length fields and they are unaware of this.
> 
> No encapsulation device expresses support for handling offloaded
> encapsulated packets, so we won't generate these types of frames
> in the transmit path. However, GRO doesn't have a check for
> multiple levels of encapsulation and will attempt to build them.
> 
> UDP tunnel GRO actually does prevent this situation but it only
> handles multiple UDP tunnels stacked on top of each other. This
> generalizes that solution to prevent any kind of tunnel stacking
> that would cause problems.
> 
> Fixes: bf5a755f ("net-gre-gro: Add GRE support to the GRO stack")
> Signed-off-by: Jesse Gross <jesse@kernel.org>
> Signed-off-by: David S. Miller <davem@davemloft.net>


-- 
Regards,
Thomas


[-- Attachment #2: OpenPGP digital signature --]
[-- Type: application/pgp-signature, Size: 951 bytes --]

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2017-01-20  8:38 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-01-10  2:09 Patch "tunnels: Don't apply GRO to multiple layers of encapsulation" (CVE-2016-8666) is missing in 4.1 and 3.18 stable tree Thomas Deutschmann
2017-01-10  6:45 ` Greg KH
     [not found]   ` <20170112170836.5dzdxjfcrbx6en3c@sasha-lappy>
2017-01-19 23:14     ` [E] " Seung-Woo Kim
2017-01-20  8:28       ` Greg KH

This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.