Netdev List
 help / color / mirror / Atom feed
* [PATCH net] net: ipv4: do not send ICMP Redirect when peer allocation fails
@ 2026-07-23 12:06 Eric Dumazet
  2026-07-23 12:43 ` Eric Dumazet
  0 siblings, 1 reply; 2+ messages in thread
From: Eric Dumazet @ 2026-07-23 12:06 UTC (permalink / raw)
  To: David S . Miller, Jakub Kicinski, Paolo Abeni
  Cc: Simon Horman, Ido Schimmel, David Ahern, netdev, eric.dumazet,
	Eric Dumazet

When inet_getpeer_v4() fails to allocate a peer entry under memory pressure
or tree size caps, ip_rt_send_redirect() previously fell back to sending an
un-rate-limited ICMP Redirect.

Because ICMP Redirect is not part of the global rate limit mask (sysctl_icmp_ratemask),
sending ICMP Redirects when peer == NULL creates an un-rate-limited ICMP packet storm.

Fix this by failing closed in ip_rt_send_redirect() when peer == NULL.

Fixes: a853c609504e ("inetpeer: do not get a refcount in inet_getpeer()")
Signed-off-by: Eric Dumazet <edumazet@google.com>
---
 net/ipv4/route.c | 2 --
 1 file changed, 2 deletions(-)

diff --git a/net/ipv4/route.c b/net/ipv4/route.c
index 3f3de5164d6e5854cae3ebe6fcecbac10fb63418..152d8cb28f65aacee378521e16885c9cf1a4870e 100644
--- a/net/ipv4/route.c
+++ b/net/ipv4/route.c
@@ -892,8 +892,6 @@ void ip_rt_send_redirect(struct sk_buff *skb)
 	peer = inet_getpeer_v4(net->ipv4.peers, ip_hdr(skb)->saddr, vif);
 	if (!peer) {
 		rcu_read_unlock();
-		icmp_send(skb, ICMP_REDIRECT, ICMP_REDIR_HOST,
-			  rt_nexthop(rt, ip_hdr(skb)->daddr));
 		return;
 	}
 
-- 
2.55.0.229.g6434b31f56-goog


^ permalink raw reply related	[flat|nested] 2+ messages in thread

* Re: [PATCH net] net: ipv4: do not send ICMP Redirect when peer allocation fails
  2026-07-23 12:06 [PATCH net] net: ipv4: do not send ICMP Redirect when peer allocation fails Eric Dumazet
@ 2026-07-23 12:43 ` Eric Dumazet
  0 siblings, 0 replies; 2+ messages in thread
From: Eric Dumazet @ 2026-07-23 12:43 UTC (permalink / raw)
  To: David S . Miller, Jakub Kicinski, Paolo Abeni
  Cc: Simon Horman, Ido Schimmel, David Ahern, netdev, eric.dumazet

On Thu, Jul 23, 2026 at 2:06 PM Eric Dumazet <edumazet@google.com> wrote:
>
> When inet_getpeer_v4() fails to allocate a peer entry under memory pressure
> or tree size caps, ip_rt_send_redirect() previously fell back to sending an
> un-rate-limited ICMP Redirect.
>
> Because ICMP Redirect is not part of the global rate limit mask (sysctl_icmp_ratemask),
> sending ICMP Redirects when peer == NULL creates an un-rate-limited ICMP packet storm.
>
> Fix this by failing closed in ip_rt_send_redirect() when peer == NULL.
>
> Fixes: a853c609504e ("inetpeer: do not get a refcount in inet_getpeer()")
> Signed-off-by: Eric Dumazet <edumazet@google.com>
> ---
>  net/ipv4/route.c | 2 --
>  1 file changed, 2 deletions(-)

I think I sent this patch too soon, I will send a V2 tomorrow.
--
pw-bot: cr

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-07-23 12:43 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-07-23 12:06 [PATCH net] net: ipv4: do not send ICMP Redirect when peer allocation fails Eric Dumazet
2026-07-23 12:43 ` Eric Dumazet

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox