Linux Kernel Selftest development
 help / color / mirror / Atom feed
* [PATCH net v2 0/2] tls: fix plaintext sk_msg ring over-fill
@ 2026-08-04  5:28 chanyoung
  2026-08-04  5:28 ` [PATCH net v2 1/2] tls: don't leave a full plaintext sk_msg ring unpushed chanyoung
                   ` (2 more replies)
  0 siblings, 3 replies; 4+ messages in thread
From: chanyoung @ 2026-08-04  5:28 UTC (permalink / raw)
  To: netdev
  Cc: Sabrina Dubroca, Jakub Kicinski, John Fastabend, David Howells,
	Shuah Khan, linux-kselftest, chanyoung

An unprivileged user can oops the kernel by splicing into a kTLS socket
whose open record already has a full plaintext sk_msg ring.  Reproduced on
net (53658c6f3682) with a stock config, no KASAN.

Patch 2 oopses an unpatched kernel and passes with patch 1 applied.

v2:
  - fix the copy path so a full record is never left unpushed, rather than
    making tls_sw_sendmsg_splice() tolerate a full ring (Sabrina)
  - selftest: drop the comments, one splice instead of four, reuse a single
    pipe, compare the whole blob, sweep 16..44 fragments
v1: https://lore.kernel.org/netdev/20260726105556.2719227-1-ppoo1220@gmail.com/

chanyoung (2):
  tls: don't leave a full plaintext sk_msg ring unpushed
  selftests: tls: add a test for splicing onto a full plaintext record

 net/tls/tls_sw.c                  | 14 ++++++++++++
 tools/testing/selftests/net/tls.c | 37 +++++++++++++++++++++++++++++++
 2 files changed, 51 insertions(+)

-- 
2.43.0


^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-08-06 16:10 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-08-04  5:28 [PATCH net v2 0/2] tls: fix plaintext sk_msg ring over-fill chanyoung
2026-08-04  5:28 ` [PATCH net v2 1/2] tls: don't leave a full plaintext sk_msg ring unpushed chanyoung
2026-08-04  5:28 ` [PATCH net v2 2/2] selftests: tls: add a test for splicing onto a full plaintext record chanyoung
2026-08-06 16:10 ` [PATCH net v2 0/2] tls: fix plaintext sk_msg ring over-fill patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox