* [PATCH iwl-net v2] e1000e: fix NETIF_F_RXALL buffer overrun
@ 2026-09-17 10:51 Matt Vollrath
2026-09-18 15:46 ` Loktionov, Aleksandr
0 siblings, 1 reply; 2+ messages in thread
From: Matt Vollrath @ 2026-09-17 10:51 UTC (permalink / raw)
To: intel-wired-lan
Cc: netdev, Tony Nguyen, Przemek Kitszel, Andrew Lunn,
David S . Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
Ben Greear, Matt Vollrath, stable
When SBP is set, the card may deliver frames which would otherwise be
filtered out by LPE being unset. This would allow the device to write
up to 526 bytes beyond the skb's data allocation: over its own shinfo,
and beyond. This bug is reachable only when MTU <= 1500 and
NETIF_F_RXALL is set by ethtool.
To reproduce, build a kernel with CONFIG_SLUB_DEBUG=y and boot with
slub_debug=FZP. Enable RXALL with 'ethtool -K <iface> rx-all on'. Leave
MTU at 1500. Directly link with a remote machine and set the remote
link to MTU 9000. Send oversized frames from the remote machine with
'ping -f -M do -s 8972 -p 00'. Unload e1000e on the machine under test.
Observe slub_debug faults in 'dmesg'. If IOMMU is enabled, you may also
see IOMMU faults during pings.
Fix this by ensuring that buffers are large enough for an entire 2048
byte chunk when NETIF_F_RXALL is set. Do this by moving final
rx_buffer_len determination to one place, right before RCTL.BSIZE is
determined. This will correctly re-evaluate every time the adapter is
configured, not just on MTU change.
Signed-off-by: Matt Vollrath <tactii@gmail.com>
Suggested-by: Jakub Kicinski <kuba@kernel.org>
Assisted-by: Claude:claude-5-1-fable
Fixes: cf955e6c96cb ("e1000e: Support RXALL feature flag.")
Cc: stable@vger.kernel.org
---
v2:
* Don't make a new function for setting rx_buffer_len.
* Rewording.
* Add steps to reproduce.
---
drivers/net/ethernet/intel/e1000e/netdev.c | 41 +++++++++++-----------
1 file changed, 20 insertions(+), 21 deletions(-)
diff --git a/drivers/net/ethernet/intel/e1000e/netdev.c b/drivers/net/ethernet/intel/e1000e/netdev.c
index 844f31ab37ad..f31dd5886b09 100644
--- a/drivers/net/ethernet/intel/e1000e/netdev.c
+++ b/drivers/net/ethernet/intel/e1000e/netdev.c
@@ -3094,6 +3094,23 @@ static void e1000_setup_rctl(struct e1000_adapter *adapter)
e1e_wphy(hw, 22, phy_data);
}
+ /* NOTE: netdev_alloc_skb reserves 16 bytes, and typically NET_IP_ALIGN
+ * means we reserve 2 more, this pushes us to allocate from the next
+ * larger slab size.
+ * i.e. RXBUFFER_2048 --> size-4096 slab
+ * However with the new *_jumbo_rx* routines, jumbo receives will use
+ * fragmented skbs
+ */
+ if (adapter->max_frame_size <= 2048)
+ adapter->rx_buffer_len = 2048;
+ else
+ adapter->rx_buffer_len = 4096;
+
+ /* adjust allocation if LPE protects us, and we aren't using SBP */
+ if (adapter->max_frame_size <= (VLAN_ETH_FRAME_LEN + ETH_FCS_LEN) &&
+ !(adapter->netdev->features & NETIF_F_RXALL))
+ adapter->rx_buffer_len = VLAN_ETH_FRAME_LEN + ETH_FCS_LEN;
+
/* Setup buffer sizes */
rctl &= ~E1000_RCTL_SZ_4096;
rctl |= E1000_RCTL_BSEX;
@@ -6079,30 +6096,12 @@ static int e1000_change_mtu(struct net_device *netdev, int new_mtu)
pm_runtime_get_sync(netdev->dev.parent);
- if (netif_running(netdev))
+ if (netif_running(netdev)) {
e1000e_down(adapter, true);
-
- /* NOTE: netdev_alloc_skb reserves 16 bytes, and typically NET_IP_ALIGN
- * means we reserve 2 more, this pushes us to allocate from the next
- * larger slab size.
- * i.e. RXBUFFER_2048 --> size-4096 slab
- * However with the new *_jumbo_rx* routines, jumbo receives will use
- * fragmented skbs
- */
-
- if (max_frame <= 2048)
- adapter->rx_buffer_len = 2048;
- else
- adapter->rx_buffer_len = 4096;
-
- /* adjust allocation if LPE protects us, and we aren't using SBP */
- if (max_frame <= (VLAN_ETH_FRAME_LEN + ETH_FCS_LEN))
- adapter->rx_buffer_len = VLAN_ETH_FRAME_LEN + ETH_FCS_LEN;
-
- if (netif_running(netdev))
e1000e_up(adapter);
- else
+ } else {
e1000e_reset(adapter);
+ }
pm_runtime_put_sync(netdev->dev.parent);
--
2.43.0
^ permalink raw reply related [flat|nested] 2+ messages in thread
* RE: [PATCH iwl-net v2] e1000e: fix NETIF_F_RXALL buffer overrun
2026-09-17 10:51 [PATCH iwl-net v2] e1000e: fix NETIF_F_RXALL buffer overrun Matt Vollrath
@ 2026-09-18 15:46 ` Loktionov, Aleksandr
0 siblings, 0 replies; 2+ messages in thread
From: Loktionov, Aleksandr @ 2026-09-18 15:46 UTC (permalink / raw)
To: Matt Vollrath, intel-wired-lan@lists.osuosl.org
Cc: netdev@vger.kernel.org, Nguyen, Anthony L, Kitszel, Przemyslaw,
Andrew Lunn, David S . Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Ben Greear, stable@vger.kernel.org
> -----Original Message-----
> From: Matt Vollrath <tactii@gmail.com>
> Sent: Thursday, September 17, 2026 12:52 PM
> To: intel-wired-lan@lists.osuosl.org
> Cc: netdev@vger.kernel.org; Nguyen, Anthony L
> <anthony.l.nguyen@intel.com>; Kitszel, Przemyslaw
> <przemyslaw.kitszel@intel.com>; Andrew Lunn <andrew+netdev@lunn.ch>;
> David S . Miller <davem@davemloft.net>; Eric Dumazet
> <edumazet@google.com>; Jakub Kicinski <kuba@kernel.org>; Paolo Abeni
> <pabeni@redhat.com>; Ben Greear <greearb@candelatech.com>; Matt
> Vollrath <tactii@gmail.com>; stable@vger.kernel.org
> Subject: [PATCH iwl-net v2] e1000e: fix NETIF_F_RXALL buffer overrun
>
> When SBP is set, the card may deliver frames which would otherwise be
> filtered out by LPE being unset. This would allow the device to write
> up to 526 bytes beyond the skb's data allocation: over its own shinfo,
> and beyond. This bug is reachable only when MTU <= 1500 and
> NETIF_F_RXALL is set by ethtool.
>
> To reproduce, build a kernel with CONFIG_SLUB_DEBUG=y and boot with
> slub_debug=FZP. Enable RXALL with 'ethtool -K <iface> rx-all on'.
> Leave MTU at 1500. Directly link with a remote machine and set the
> remote link to MTU 9000. Send oversized frames from the remote machine
> with 'ping -f -M do -s 8972 -p 00'. Unload e1000e on the machine under
> test.
> Observe slub_debug faults in 'dmesg'. If IOMMU is enabled, you may
> also see IOMMU faults during pings.
>
> Fix this by ensuring that buffers are large enough for an entire 2048
> byte chunk when NETIF_F_RXALL is set. Do this by moving final
> rx_buffer_len determination to one place, right before RCTL.BSIZE is
> determined. This will correctly re-evaluate every time the adapter is
> configured, not just on MTU change.
>
> Signed-off-by: Matt Vollrath <tactii@gmail.com>
> Suggested-by: Jakub Kicinski <kuba@kernel.org>
> Assisted-by: Claude:claude-5-1-fable
> Fixes: cf955e6c96cb ("e1000e: Support RXALL feature flag.")
> Cc: stable@vger.kernel.org
> ---
> v2:
> * Don't make a new function for setting rx_buffer_len.
> * Rewording.
> * Add steps to reproduce.
> ---
> drivers/net/ethernet/intel/e1000e/netdev.c | 41 +++++++++++----------
> -
> 1 file changed, 20 insertions(+), 21 deletions(-)
>
> diff --git a/drivers/net/ethernet/intel/e1000e/netdev.c
> b/drivers/net/ethernet/intel/e1000e/netdev.c
> index 844f31ab37ad..f31dd5886b09 100644
> --- a/drivers/net/ethernet/intel/e1000e/netdev.c
> +++ b/drivers/net/ethernet/intel/e1000e/netdev.c
> @@ -3094,6 +3094,23 @@ static void e1000_setup_rctl(struct
> e1000_adapter *adapter)
> e1e_wphy(hw, 22, phy_data);
> }
>
> + /* NOTE: netdev_alloc_skb reserves 16 bytes, and typically
> NET_IP_ALIGN
> + * means we reserve 2 more, this pushes us to allocate from the
> next
> + * larger slab size.
> + * i.e. RXBUFFER_2048 --> size-4096 slab
> + * However with the new *_jumbo_rx* routines, jumbo receives
> will use
> + * fragmented skbs
> + */
> + if (adapter->max_frame_size <= 2048)
> + adapter->rx_buffer_len = 2048;
> + else
> + adapter->rx_buffer_len = 4096;
> +
> + /* adjust allocation if LPE protects us, and we aren't using
> SBP */
> + if (adapter->max_frame_size <= (VLAN_ETH_FRAME_LEN +
> ETH_FCS_LEN) &&
> + !(adapter->netdev->features & NETIF_F_RXALL))
> + adapter->rx_buffer_len = VLAN_ETH_FRAME_LEN +
> ETH_FCS_LEN;
> +
> /* Setup buffer sizes */
> rctl &= ~E1000_RCTL_SZ_4096;
> rctl |= E1000_RCTL_BSEX;
> @@ -6079,30 +6096,12 @@ static int e1000_change_mtu(struct net_device
> *netdev, int new_mtu)
>
> pm_runtime_get_sync(netdev->dev.parent);
>
> - if (netif_running(netdev))
> + if (netif_running(netdev)) {
> e1000e_down(adapter, true);
> -
> - /* NOTE: netdev_alloc_skb reserves 16 bytes, and typically
> NET_IP_ALIGN
> - * means we reserve 2 more, this pushes us to allocate from the
> next
> - * larger slab size.
> - * i.e. RXBUFFER_2048 --> size-4096 slab
> - * However with the new *_jumbo_rx* routines, jumbo receives
> will use
> - * fragmented skbs
> - */
> -
> - if (max_frame <= 2048)
> - adapter->rx_buffer_len = 2048;
> - else
> - adapter->rx_buffer_len = 4096;
> -
> - /* adjust allocation if LPE protects us, and we aren't using
> SBP */
> - if (max_frame <= (VLAN_ETH_FRAME_LEN + ETH_FCS_LEN))
> - adapter->rx_buffer_len = VLAN_ETH_FRAME_LEN +
> ETH_FCS_LEN;
> -
> - if (netif_running(netdev))
> e1000e_up(adapter);
> - else
> + } else {
> e1000e_reset(adapter);
> + }
>
> pm_runtime_put_sync(netdev->dev.parent);
>
> --
> 2.43.0
Reviewed-by: Aleksandr Loktionov <aleksandr.loktionov@intel.com>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-09-18 15:47 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-17 10:51 [PATCH iwl-net v2] e1000e: fix NETIF_F_RXALL buffer overrun Matt Vollrath
2026-09-18 15:46 ` Loktionov, Aleksandr
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox