From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 79EB455D86E; Wed, 30 Sep 2026 17:46:46 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790790407; cv=none; b=qceJqHpwD45h/AM+SPTpkM5g6rvbrzqu5b83IbA6DJhd/BKucCcVdZk93jE+6LLP0W/rbTreNiD8DIdZGZXk6DKhko8DiLMSLFeUIHY4Sk8GM6Lba9U9O57KbJAsG2K09WMP/X+BTtxLWvexvqzO9zqld7I5uYGGcuTQzn8uH+Q= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1790790407; c=relaxed/simple; bh=/65TUdL28ErBzA1of4bsD4Rgi/rip8QRNpA3L4jkWQ0=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=f8JWemhXpHpqSjyYFn8TLAZN8VzLsAmxz8n5md8qFGbZ8TnLHbTFXowABx/nEVIELRBLBbEK36ngYZ/vexSLz9KFhZkiFgXj5D2IiicFcDRMTYnUhFJd9QMfe7jAl/vNKgMHXA1HNisZlyUDvtk4t2/BAsQzcMf9EwH7ZN15vEE= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=n1fZQBZR; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="n1fZQBZR" Received: by smtp.kernel.org (Postfix) with ESMTPSA id D28401F000FF; Wed, 30 Sep 2026 17:46:45 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1790790406; bh=EcU0mpq59jGTG5n3RaTfWm/9s291crLcvGKPFhTGpT0=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=n1fZQBZRB0RpiWueSn5nIAOVSUf77QcL2HWh7OaDUu3xLfNyOEA03h4Jpo9/eMVic O8+AC6mlQOp2h0ZCf3kqQlKRZ3cqkC5o7Ks1KS3iXFdR1dJZ9ytLiEudox2z2kVyxb 8ikgO1EdEs70XU35lvsX2X3bRbJ5GFKl7wzpbjL0= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, co+0ea1ac045375cf05@bugs.sh, Xiang Mei , Simon Horman , Jakub Kicinski , Sasha Levin Subject: [PATCH 6.12 817/877] vlan: require the MAC header to be present in __vlan_insert_inner_tag() Date: Wed, 30 Sep 2026 17:28:48 +0200 Message-ID: <20260930152432.356317639@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260930152414.738996857@linuxfoundation.org> References: <20260930152414.738996857@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 6.12-stable review patch. If anyone has any objections, please let me know. ------------------ From: Xiang Mei [ Upstream commit ab888242fce4f16f6c4d4c6ec53939ad36aa3b3a ] __vlan_insert_inner_tag() only guarantees head room via skb_cow_head(), never that mac_len bytes of MAC header are present. Its ETH_HLEN wrappers - __vlan_insert_tag() under skb_vlan_push(), and vlan_insert_tag() under validate_xmit_vlan() on the generic transmit path - therefore rewrite the first 16 bytes at skb->data: a 12-byte memmove plus two 2-byte stores at +12 and +14. No caller supplies the bound, while the pop helpers use skb_ensure_writable()/pskb_may_pull(). An IFF_TUN device has hard_header_len == 0, so packet_snd() accepts a one-byte AF_PACKET/SOCK_RAW frame. The first vlan push only sets a hwaccel tag; the next - clsact "action vlan push" or bpf_skb_vlan_push() - enters the helper with skb->len still 1. The head comes from skbuff_small_head without __GFP_ZERO, so each push drags bytes from beyond skb->tail into the frame. After three the one-byte send leaves as 13 bytes carrying 11 bytes of uninitialised slab: 0000: 5a b3 62 12 80 88 ff ff 00 b3 62 12 81 `------------------------------' only 0x5a was sent; the rest is slab, here the top 56 bits of a linear-map address Require the MAC header the helper rewrites to be present, so such a frame is dropped rather than transmitted. Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") Cc: stable@vger.kernel.org Reported-by: co+0ea1ac045375cf05@bugs.sh Signed-off-by: Xiang Mei Reviewed-by: Simon Horman Link: https://patch.msgid.link/20260915083152.705309-1-xmei5@asu.edu Signed-off-by: Jakub Kicinski [ adjusted context around skb_cow_head(skb, VLAN_HLEN) because the branch lacks upstream meta_len handling. ] Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- include/linux/if_vlan.h | 3 +++ 1 file changed, 3 insertions(+) --- a/include/linux/if_vlan.h +++ b/include/linux/if_vlan.h @@ -356,6 +356,9 @@ static inline int __vlan_insert_inner_ta { struct vlan_ethhdr *veth; + if (unlikely(!pskb_may_pull(skb, mac_len))) + return -EINVAL; + if (skb_cow_head(skb, VLAN_HLEN) < 0) return -ENOMEM;