All of lore.kernel.org
 help / color / mirror / Atom feed
From: Qingfang Deng <qingfang.deng@linux.dev>
To: Vlatko Kosturjak <kost@linux.hr>,
	linux-ppp@vger.kernel.org, netdev@vger.kernel.org
Cc: Eric Dumazet <edumazet@google.com>,
	Andrew Lunn <andrew+netdev@lunn.ch>,
	"David S. Miller" <davem@davemloft.net>,
	Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>,
	linux-kernel@vger.kernel.org
Subject: Re: [PATCH net v2] ppp_async: drop the errored frame instead of resetting its headroom
Date: Thu, 3 Sep 2026 16:24:55 +0800	[thread overview]
Message-ID: <e10b5f72-adbd-46a5-9364-3580ff16a765@linux.dev> (raw)
In-Reply-To: <apkR6ZU+tqP2C3Fl@griffin.linux.hr>

Hi,

On 2026/9/3 14:21, Vlatko Kosturjak wrote:
> ppp_receive_nonmp_frame() prepends a two-byte direction tag before running
> the pass/active BPF filters:
>
> 	*(__be16 *)skb_push(skb, 2) = htons(PPP_FILTER_INBOUND_TAG);
>
> Nothing on the receive path guarantees those two bytes of headroom. The
> frame-error path in ppp_async's process_input_packet() resets a reused skb's
> headroom to zero while claiming to restore it to a freshly allocated state -
> but a fresh skb from dev_alloc_skb() carries NET_SKB_PAD:
>
> 	err:
> 		if (skb) {
> 			/* make skb appear as freshly allocated */
> 			skb_trim(skb, 0);
> 			skb_reserve(skb, - skb_headroom(skb));
> 		}
>
> ap->rpkt still points at that skb, so the next frame is reassembled into it
> with no headroom at all. A peer that sends a bad-FCS frame followed by one
> beginning ff 03 then leaves a single byte of headroom by the time the filter
> tag is pushed, which lands one byte below skb->head:
>
>    skbuff: skb_under_panic: len:49 put:2 head:ffff888003c10000
>            data:ffff888003c0ffff tail:0x30 end:0x640 dev:<NULL>
>    kernel BUG at net/core/skbuff.c:214!
>    RIP: 0010:skb_panic+0x13e/0x230
>    Call Trace:
>     skb_push+0xbd/0x100
>     ppp_receive_nonmp_frame+0x48a/0x1d10
>     ppp_input+0x4e9/0x2f80
>     ppp_async_process+0x2a/0xe0
>     tasklet_action_common+0x20f/0x8a0
>     handle_softirqs+0x18e/0x590
>    Kernel panic - not syncing: Fatal exception in interrupt
>
> Zeroing the headroom violates the NET_SKB_PAD guarantee that dev_alloc_skb()
> gives the rest of the receive path. Besides the filter panic above, when CCP
> compression is enabled ppp_decompress_frame() hands skb->data - 2 to
> ->decompress()/->incomp(), which then reads out of bounds before skb->head
> for the same reason.
>
> Rather than restore the headroom, drop the errored frame - as ppp_synctty
> already does on its error path - and clear ap->rpkt so the next frame is
> reassembled into a fresh skb with proper headroom. This is simpler and fixes
> both the filter under-panic and the CCP out-of-bounds read.
>
> The original V1 of this patch made room in ppp_receive_nonmp_frame() with
> skb_cow_head(); Eric pointed out that fixing the root cause in the transport
> is the right approach.
>
> Found by fuzzing the PPP receive path with a mutating peer on a pty; it is an
> interesting (remote) DoS: root configures PPP, the peer supplies two crashing
> frames. The reproducer (repro-ppp-skb.c, unchanged from v1) panics in about a
> second, and returns cleanly with this applied.
>
> Fixes: 6722e78c9005 ("[PPP]: handle misaligned accesses")

Nit: the skb->len == 0 alignment check introduced by said commit is now 
redundant and can be moved back into the allocation branch.

> Suggested-by: Eric Dumazet <edumazet@google.com>
> Signed-off-by: Vlatko Kosturjak <kost@linux.hr>
Kind regards,

  reply	other threads:[~2026-09-03  8:25 UTC|newest]

Thread overview: 4+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-09-03  6:21 [PATCH net v2] ppp_async: drop the errored frame instead of resetting its headroom Vlatko Kosturjak
2026-09-03  8:24 ` Qingfang Deng [this message]
2026-09-03  8:44 ` Eric Dumazet
2026-09-08 23:50 ` patchwork-bot+netdevbpf

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=e10b5f72-adbd-46a5-9364-3580ff16a765@linux.dev \
    --to=qingfang.deng@linux.dev \
    --cc=andrew+netdev@lunn.ch \
    --cc=davem@davemloft.net \
    --cc=edumazet@google.com \
    --cc=kost@linux.hr \
    --cc=kuba@kernel.org \
    --cc=linux-kernel@vger.kernel.org \
    --cc=linux-ppp@vger.kernel.org \
    --cc=netdev@vger.kernel.org \
    --cc=pabeni@redhat.com \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.