All of lore.kernel.org
 help / color / mirror / Atom feed
From: Vadim Fedorenko <vadim.fedorenko@linux.dev>
To: Asim Viladi Oglu Manizada <manizada@pm.me>, netdev@vger.kernel.org
Cc: Andrew Lunn <andrew+netdev@lunn.ch>,
	"David S. Miller" <davem@davemloft.net>,
	Eric Dumazet <edumazet@google.com>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH net] pppoe: reload header pointer after dev_hard_header()
Date: Wed, 22 Jul 2026 12:17:28 +0100	[thread overview]
Message-ID: <2c8655e9-208a-440e-bbeb-d72019e0131e@linux.dev> (raw)
In-Reply-To: <20260722093814.3017176-1-manizada@pm.me>

On 22/07/2026 10:38, Asim Viladi Oglu Manizada wrote:
> pppoe_sendmsg() saves a pointer to the PPPoE header before calling
> dev_hard_header(). Device header callbacks are allowed to reallocate the
> skb head, invalidating pointers into it.
> 
> This can happen when a send is blocked in copy_from_user() while the first
> non-Ethernet port is added to an empty team device. The team's delegated
> GRE header callback then expands the skb head. PPPoE subsequently writes
> six bytes through the stale pointer into the freed head.
> 
> Reload the PPPoE header through the skb's network-header offset after
> device header creation. pskb_expand_head() updates that offset when it
> relocates the head.
> 
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Cc: stable@vger.kernel.org
> Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
> Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
> ---
>   drivers/net/ppp/pppoe.c | 1 +
>   1 file changed, 1 insertion(+)
> 
> diff --git a/drivers/net/ppp/pppoe.c b/drivers/net/ppp/pppoe.c
> index 4a018acb5..6874a1a8e 100644
> --- a/drivers/net/ppp/pppoe.c
> +++ b/drivers/net/ppp/pppoe.c
> @@ -825,6 +825,7 @@ static int pppoe_sendmsg(struct socket *sock, struct msghdr *m,
>   	dev_hard_header(skb, dev, ETH_P_PPP_SES,
>   			po->pppoe_pa.remote, NULL, total_len);
>   
> +	ph = pppoe_hdr(skb);
>   	memcpy(ph, &hdr, sizeof(struct pppoe_hdr));
>   
>   	ph->length = htons(total_len);
Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>

  reply	other threads:[~2026-07-22 11:17 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-22  9:38 [PATCH net] pppoe: reload header pointer after dev_hard_header() Asim Viladi Oglu Manizada
2026-07-22 11:17 ` Vadim Fedorenko [this message]
2026-07-22 12:31   ` Eric Dumazet

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=2c8655e9-208a-440e-bbeb-d72019e0131e@linux.dev \
    --to=vadim.fedorenko@linux.dev \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=manizada@pm.me \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.