From: "Pablo Vallespín Aranguren" <pablopva014@gmail.com>
To: David Laight <david.laight.linux@gmail.com>
Cc: Andrew Lunn <andrew+netdev@lunn.ch>,
"David S. Miller" <davem@davemloft.net>,
Eric Dumazet <edumazet@google.com>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
"open list:TULIP NETWORK DRIVERS" <netdev@vger.kernel.org>,
"open list:TULIP NETWORK DRIVERS" <linux-parisc@vger.kernel.org>,
open list <linux-kernel@vger.kernel.org>,
Greg KH <gregkh@linuxfoundation.org>
Subject: Re: [PATCH] net: tulip: xircom_cb: drop runt frames before skb copy
Date: Fri, 31 Jul 2026 22:56:02 +0200 [thread overview]
Message-ID: <am0L4gNtPJaMPx_9@ThinkPad-P15> (raw)
In-Reply-To: <20260731202629.10ff97e6@pumpkin>
On Fri, Jul 31, 2026 at 08:26:29PM +0100, David Laight wrote:
> On Fri, 31 Jul 2026 20:33:34 +0200
> Pablo Vallespín Aranguren <pablopva014@gmail.com> wrote:
>
> Have you checked that that hardware can actually set a short value?
> I'd expect that packets shorter than 64 bytes (including the crc) are
> dropped as 'runts' and probably don't even use a ring entry.
I haven't verified how the real Xircom firmware handles runt frames (I
don't own this hardware). I tested with Qemu's emulated NIC, the device
itself does validate and reject negative-size values before sending them
to the driver.
> Of course, if you think the device might lie all bets are off.
> (Without an iommu is can write anywhere in host memory...)
I took into account that the hardware could glitch or a misbehaving/fake
card could be used. I modified the emulated NIC to mimic this behaviour,
and given that the driver does not perform a check on its own (to
validate that pkt_len is not negative) it does lead to a kernel panic.
Best,
Pablo
> > Signed-off-by: Pablo Vallespín Aranguren <pablopva014@gmail.com>
> > Assisted-by: gkh_clanker_t1000
> > ---
> > drivers/net/ethernet/dec/tulip/xircom_cb.c | 5 +++++
> > 1 file changed, 5 insertions(+)
> >
> > diff --git a/drivers/net/ethernet/dec/tulip/xircom_cb.c b/drivers/net/ethernet/dec/tulip/xircom_cb.c
> > index e5d2ede13845..62c64da1c8fa 100644
> > --- a/drivers/net/ethernet/dec/tulip/xircom_cb.c
> > +++ b/drivers/net/ethernet/dec/tulip/xircom_cb.c
> > @@ -1110,6 +1110,11 @@ investigate_read_descriptor(struct net_device *dev, struct xircom_private *card,
> > /* minus 4, we don't want the CRC */
> > struct sk_buff *skb;
> >
> > + if (pkt_len < 0) {
> > + dev->stats.rx_length_errors++;
> > + goto out;
> > + }
> > +
> > if (pkt_len > 1518) {
> > netdev_err(dev, "Packet length %i is bogus\n", pkt_len);
> > pkt_len = 1518;
>
next prev parent reply other threads:[~2026-07-31 20:56 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-31 18:33 [PATCH] net: tulip: xircom_cb: drop runt frames before skb copy Pablo Vallespín Aranguren
2026-07-31 19:26 ` David Laight
2026-07-31 20:56 ` Pablo Vallespín Aranguren [this message]
2026-07-31 23:55 ` Jakub Kicinski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=am0L4gNtPJaMPx_9@ThinkPad-P15 \
--to=pablopva014@gmail.com \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=david.laight.linux@gmail.com \
--cc=edumazet@google.com \
--cc=gregkh@linuxfoundation.org \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=linux-parisc@vger.kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.