* [PATCH net] fou: ensure GUE headers have enough headroom
@ 2026-08-01 6:01 Chengfeng Ye
0 siblings, 0 replies; only message in thread
From: Chengfeng Ye @ 2026-08-01 6:01 UTC (permalink / raw)
To: David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Simon Horman, Kuniyuki Iwashima, Richard Gobert, Xuanqiang Luo,
Chengfeng Ye, Xin Long, William Tu
Cc: netdev, linux-kernel, stable
ipgre_changelink() installs GUE encapsulation before it publishes the
new GRE header length and updates dev->needed_headroom. The transmit
path does not serialize with RTNL, so it can interleave as follows:
CPU 0 (ipgre_changelink) CPU 1 (ipgre_xmit)
install GUE encapsulation
reserve the old needed_headroom
publish larger GRE flags
update tunnel->tun_hlen
push the larger GRE header
push the GUE and UDP headers
update dev->needed_headroom
With REMCSUM, the new layout can push 16 bytes of GRE and 20 bytes of
GUE/UDP headers into an skb with only 32 bytes of actual headroom. The
final UDP push writes four bytes before skb->head.
With the update window widened, the kernel reported:
skbuff: skb_under_panic: ... len:128 put:8 ... dev:gre0poc
kernel BUG at net/core/skbuff.c:214!
Oops: invalid opcode: 0000 [#1] SMP KASAN NOPTI
Call Trace:
skb_push
fou_build_udp
gue_build_header
ip_tunnel_xmit
__gre_xmit
ipgre_xmit
Make __gue_build_header() ensure space for both the GUE header it is
about to push and the UDP header that follows. On normally sized skbs
the check is a no-op. If configuration changes race with transmission,
skb_cow_head() expands the head before either GUE write, or returns an
error without modifying the packet.
Fixes: dd9d598c6657 ("ip_gre: add the support for i/o_flags update via netlink")
Cc: stable@vger.kernel.org
Assisted-by: Codex:gpt-5
Signed-off-by: Chengfeng Ye <nicoyip.dev@gmail.com>
---
net/ipv4/fou_core.c | 2 ++
1 file changed, 2 insertions(+)
diff --git a/net/ipv4/fou_core.c b/net/ipv4/fou_core.c
index ab09dfcdecbd..8cf0d43acb41 100644
--- a/net/ipv4/fou_core.c
+++ b/net/ipv4/fou_core.c
@@ -980,6 +980,8 @@ int __gue_build_header(struct sk_buff *skb, struct ip_tunnel_encap *e,
skb, 0, 0, false);
hdrlen = sizeof(struct guehdr) + optlen;
+ if (skb_cow_head(skb, hdrlen + sizeof(struct udphdr)))
+ return -ENOMEM;
skb_push(skb, hdrlen);
--
2.43.0
^ permalink raw reply related [flat|nested] only message in thread
only message in thread, other threads:[~2026-08-01 6:02 UTC | newest]
Thread overview: (only message) (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-01 6:01 [PATCH net] fou: ensure GUE headers have enough headroom Chengfeng Ye
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.