From: Vadim Fedorenko <vadim.fedorenko@linux.dev>
To: Eric Dumazet <edumazet@google.com>,
"David S . Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>
Cc: Simon Horman <horms@kernel.org>, Ido Schimmel <idosch@nvidia.com>,
Andrew Lunn <andrew+netdev@lunn.ch>,
netdev@vger.kernel.org, eric.dumazet@gmail.com,
stable@vger.kernel.org
Subject: Re: [PATCH net 5/5] vxlan: use pskb_network_may_pull() for transmit path header pulls
Date: Thu, 23 Jul 2026 17:43:55 +0100 [thread overview]
Message-ID: <f974b9e9-52e0-4f82-ac30-e84d50cee26b@linux.dev> (raw)
In-Reply-To: <20260723144249.759100-6-edumazet@google.com>
On 23/07/2026 15:42, Eric Dumazet wrote:
> In vxlan_xmit(), arp_reduce(), and vxlan_mdb_entry_skb_get(), pskb_may_pull() was
> being called to verify the availability of network layer headers (ARP, IPv6/ND,
> IP/IPv6 MDB keys).
>
> However, during transmit skb->data points to the MAC header, so skb_network_offset(skb)
> is ETH_HLEN (14 bytes). Using pskb_may_pull(skb, len) only checks len bytes from skb->data
> rather than skb_network_offset(skb) + len, which can leave part of the network header
> in non-linear frags.
>
> Replace these remaining pskb_may_pull() calls with pskb_network_may_pull() to properly
> account for the MAC header offset.
>
> Fixes: 465016142711 ("vxlan: Add ARP reduction support")
> Fixes: 9e061a50a116 ("vxlan: Add IPv6 Neighbor Discovery reduction support")
> Fixes: 4e94f09d84bf ("vxlan: add MDB support")
> Signed-off-by: Eric Dumazet <edumazet@google.com>
> Cc: stable@vger.kernel.org
> ---
> drivers/net/vxlan/vxlan_core.c | 6 +++---
> drivers/net/vxlan/vxlan_mdb.c | 4 ++--
> 2 files changed, 5 insertions(+), 5 deletions(-)
>
> diff --git a/drivers/net/vxlan/vxlan_core.c b/drivers/net/vxlan/vxlan_core.c
> index 9ccbebda860480f8378918ff360deee1c46f3f7d..eff17987c5b531ecb1e2943b6274d20c1827d299 100644
> --- a/drivers/net/vxlan/vxlan_core.c
> +++ b/drivers/net/vxlan/vxlan_core.c
> @@ -1850,7 +1850,7 @@ static int arp_reduce(struct net_device *dev, struct sk_buff *skb, __be32 vni)
> if (dev->flags & IFF_NOARP)
> goto out;
>
> - if (!pskb_may_pull(skb, arp_hdr_len(dev))) {
> + if (!pskb_network_may_pull(skb, arp_hdr_len(dev))) {
> dev_dstats_tx_dropped(dev);
> vxlan_vnifilter_count(vxlan, vni, NULL,
> VXLAN_VNI_STATS_TX_DROPS, 0);
> @@ -2763,8 +2763,8 @@ static netdev_tx_t vxlan_xmit(struct sk_buff *skb, struct net_device *dev)
> return arp_reduce(dev, skb, vni);
> #if IS_ENABLED(CONFIG_IPV6)
> else if (ntohs(eth->h_proto) == ETH_P_IPV6 &&
> - pskb_may_pull(skb, sizeof(struct ipv6hdr) +
> - sizeof(struct nd_msg)) &&
> + pskb_network_may_pull(skb, sizeof(struct ipv6hdr) +
> + sizeof(struct nd_msg)) &&
> ipv6_hdr(skb)->nexthdr == IPPROTO_ICMPV6) {
> struct nd_msg *m = (struct nd_msg *)(ipv6_hdr(skb) + 1);
>
> diff --git a/drivers/net/vxlan/vxlan_mdb.c b/drivers/net/vxlan/vxlan_mdb.c
> index af7a0d7f95a57a17486a8ecc277b7bb9d921a061..9a9038ae90c18c5f0e4362b2b254b0c48dfdad0e 100644
> --- a/drivers/net/vxlan/vxlan_mdb.c
> +++ b/drivers/net/vxlan/vxlan_mdb.c
> @@ -1631,7 +1631,7 @@ struct vxlan_mdb_entry *vxlan_mdb_entry_skb_get(struct vxlan_dev *vxlan,
>
> switch (skb->protocol) {
> case htons(ETH_P_IP):
> - if (!pskb_may_pull(skb, sizeof(struct iphdr)))
> + if (!pskb_network_may_pull(skb, sizeof(struct iphdr)))
> return NULL;
> group.dst.sa.sa_family = AF_INET;
> group.dst.sin.sin_addr.s_addr = ip_hdr(skb)->daddr;
> @@ -1640,7 +1640,7 @@ struct vxlan_mdb_entry *vxlan_mdb_entry_skb_get(struct vxlan_dev *vxlan,
> break;
> #if IS_ENABLED(CONFIG_IPV6)
> case htons(ETH_P_IPV6):
> - if (!pskb_may_pull(skb, sizeof(struct ipv6hdr)))
> + if (!pskb_network_may_pull(skb, sizeof(struct ipv6hdr)))
> return NULL;
> group.dst.sa.sa_family = AF_INET6;
> group.dst.sin6.sin6_addr = ipv6_hdr(skb)->daddr;
Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
prev parent reply other threads:[~2026-07-23 16:44 UTC|newest]
Thread overview: 10+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-23 14:42 [PATCH net 0/5] vxlan: fixes for skb header pulling, cloning, and concurrency in TX path Eric Dumazet
2026-07-23 14:42 ` [PATCH net 1/5] vxlan: re-fetch eth header after route_shortcircuit() Eric Dumazet
2026-07-23 16:37 ` Vadim Fedorenko
2026-07-23 14:42 ` [PATCH net 2/5] vxlan: unclone skb head before modifying eth header in route_shortcircuit() Eric Dumazet
2026-07-23 14:42 ` [PATCH net 3/5] vxlan: use neigh_ha_snapshot() " Eric Dumazet
2026-07-23 16:41 ` Vadim Fedorenko
2026-07-23 14:42 ` [PATCH net 4/5] vxlan: use pskb_network_may_pull() " Eric Dumazet
2026-07-23 16:42 ` Vadim Fedorenko
2026-07-23 14:42 ` [PATCH net 5/5] vxlan: use pskb_network_may_pull() for transmit path header pulls Eric Dumazet
2026-07-23 16:43 ` Vadim Fedorenko [this message]
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=f974b9e9-52e0-4f82-ac30-e84d50cee26b@linux.dev \
--to=vadim.fedorenko@linux.dev \
--cc=andrew+netdev@lunn.ch \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=eric.dumazet@gmail.com \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=stable@vger.kernel.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.