From: Vadim Fedorenko <vadim.fedorenko@linux.dev>
To: Asim Viladi Oglu Manizada <manizada@pm.me>, netdev@vger.kernel.org
Cc: Andrew Lunn <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
linux-kernel@vger.kernel.org
Subject: Re: [PATCH net] pppoe: reload header pointer after dev_hard_header()
Date: Wed, 22 Jul 2026 12:17:28 +0100 [thread overview]
Message-ID: <2c8655e9-208a-440e-bbeb-d72019e0131e@linux.dev> (raw)
In-Reply-To: <20260722093814.3017176-1-manizada@pm.me>
On 22/07/2026 10:38, Asim Viladi Oglu Manizada wrote:
> pppoe_sendmsg() saves a pointer to the PPPoE header before calling
> dev_hard_header(). Device header callbacks are allowed to reallocate the
> skb head, invalidating pointers into it.
>
> This can happen when a send is blocked in copy_from_user() while the first
> non-Ethernet port is added to an empty team device. The team's delegated
> GRE header callback then expands the skb head. PPPoE subsequently writes
> six bytes through the stale pointer into the freed head.
>
> Reload the PPPoE header through the skb's network-header offset after
> device header creation. pskb_expand_head() updates that offset when it
> relocates the head.
>
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Cc: stable@vger.kernel.org
> Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
> Signed-off-by: Asim Viladi Oglu Manizada <manizada@pm.me>
> ---
> drivers/net/ppp/pppoe.c | 1 +
> 1 file changed, 1 insertion(+)
>
> diff --git a/drivers/net/ppp/pppoe.c b/drivers/net/ppp/pppoe.c
> index 4a018acb5..6874a1a8e 100644
> --- a/drivers/net/ppp/pppoe.c
> +++ b/drivers/net/ppp/pppoe.c
> @@ -825,6 +825,7 @@ static int pppoe_sendmsg(struct socket *sock, struct msghdr *m,
> dev_hard_header(skb, dev, ETH_P_PPP_SES,
> po->pppoe_pa.remote, NULL, total_len);
>
> + ph = pppoe_hdr(skb);
> memcpy(ph, &hdr, sizeof(struct pppoe_hdr));
>
> ph->length = htons(total_len);
Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
next prev parent reply other threads:[~2026-07-22 11:17 UTC|newest]
Thread overview: 3+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-22 9:38 [PATCH net] pppoe: reload header pointer after dev_hard_header() Asim Viladi Oglu Manizada
2026-07-22 11:17 ` Vadim Fedorenko [this message]
2026-07-22 12:31 ` Eric Dumazet
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=2c8655e9-208a-440e-bbeb-d72019e0131e@linux.dev \
--to=vadim.fedorenko@linux.dev \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=manizada@pm.me \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.