Netdev List
 help / color / mirror / Atom feed
* [PATCH net v2] net: mpls: clear inner_protocol when the last label is popped
@ 2026-09-02  9:27 Fourie Zhang
  2026-09-03 11:17 ` Jiri Benc
  2026-09-04 23:10 ` patchwork-bot+netdevbpf
  0 siblings, 2 replies; 3+ messages in thread
From: Fourie Zhang @ 2026-09-02  9:27 UTC (permalink / raw)
  To: netdev, David S . Miller, Jakub Kicinski, Paolo Abeni,
	Eric Dumazet
  Cc: Jiri Benc, Simon Horman, Jamal Hadi Salim, Cong Wang, Jiri Pirko,
	Aaron Conole, Ilya Maximets, dev, stable, TencentOS Corvus AI,
	Fourie Zhang

skb_mpls_push() records the pre-encapsulation network header once, gated
on !skb->inner_protocol. skb_mpls_pop() never clears that record, so it
outlives the encapsulation it describes.

Open vSwitch can then re-push MPLS onto a packet whose
inner_network_header still points at the older, deeper offset: push a
label, pop every label, recirculate (ovs_flow_key_update() re-derives
key->eth.type and resets network_header, but leaves inner_*), then push
again. ovs_fragment() trusts the record:

	skb->network_header = skb->inner_network_header;

so skb_network_offset() goes negative. The bound check is signed:

	if (skb_network_offset(skb) > MAX_L2_LEN)

a negative offset passes it, and prepare_frag() widens the value:

	unsigned int hlen = skb_network_offset(skb);
	memcpy(&data->l2_data, skb->data, hlen);

which is a ~4GiB memcpy out of a 30-byte per-CPU buffer.

Reproduced on v7.3-rc1. RDX is the truncated length, (unsigned int)(-8):

  BUG: unable to handle page fault for address: ffffe8ffffc16000
  #PF: supervisor write access in kernel mode
  Oops: 0002 [#1] SMP KASAN NOPTI
  RIP: 0010:memcpy+0x8/0x20
  RDX: 00000000fffffff8 RSI: ffff888105d732db RDI: ffffe8ffffc16000
   prepare_frag+0x3df/0x4e0
   ovs_fragment+0x589/0x7e0
   do_output+0x4ce/0x5e0
   do_execute_actions+0x55d2/0x7b30
   ovs_execute_actions+0xea/0x450

Same root-cause shape as commit 975b5b067f52 ("ipv6: sr: restore network
header before routing and forwarding"): a stale network header offset
reaching a consumer that widens it. Here it originates in the MPLS
push/pop path.

Clear inner_protocol once the packet is no longer MPLS, so a later push
re-records the current header. net/sched/act_mpls.c is the only other
skb_mpls_pop() caller and gets the same fix; sch_frag.c saves and
restores inner_protocol around fragmentation in the same way OVS does.

Fixes: 48d2ab609b6b ("net: mpls: Fixups for GSO")
Cc: stable@vger.kernel.org
Assisted-by: tencentos-corvus-ai:hy4-preview
Signed-off-by: Fourie Zhang <fouriezhang@tencent.com>
---
v2:
  - correct the Fixes tag (Jiri Benc)
v1: https://lore.kernel.org/netdev/20260902082924.2812968-1-fouriezhang@tencent.com/

A KASAN reproducer for this issue is available if requested.

 net/core/skbuff.c | 7 +++++++
 1 file changed, 7 insertions(+)

diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 966af3beed94..cc3b4b70288b 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -6690,6 +6690,13 @@ int skb_mpls_pop(struct sk_buff *skb, __be16 next_proto, int mac_len,
 	}
 	skb->protocol = next_proto;
 
+	/* The last label is gone, so the inner header recorded by
+	 * skb_mpls_push() no longer describes this packet. Drop it, or a
+	 * later push keeps the stale offset.
+	 */
+	if (!eth_p_mpls(next_proto))
+		skb->inner_protocol = 0;
+
 	return 0;
 }
 EXPORT_SYMBOL_GPL(skb_mpls_pop);
-- 
2.43.7


^ permalink raw reply related	[flat|nested] 3+ messages in thread

* Re: [PATCH net v2] net: mpls: clear inner_protocol when the last label is popped
  2026-09-02  9:27 [PATCH net v2] net: mpls: clear inner_protocol when the last label is popped Fourie Zhang
@ 2026-09-03 11:17 ` Jiri Benc
  2026-09-04 23:10 ` patchwork-bot+netdevbpf
  1 sibling, 0 replies; 3+ messages in thread
From: Jiri Benc @ 2026-09-03 11:17 UTC (permalink / raw)
  To: Fourie Zhang
  Cc: netdev, David S . Miller, Jakub Kicinski, Paolo Abeni,
	Eric Dumazet, Simon Horman, Jamal Hadi Salim, Cong Wang,
	Jiri Pirko, Aaron Conole, Ilya Maximets, dev, stable,
	TencentOS Corvus AI, Fourie Zhang

On Wed,  2 Sep 2026 17:27:12 +0800, Fourie Zhang wrote:
> Fixes: 48d2ab609b6b ("net: mpls: Fixups for GSO")
> Cc: stable@vger.kernel.org
> Assisted-by: tencentos-corvus-ai:hy4-preview
> Signed-off-by: Fourie Zhang <fouriezhang@tencent.com>

Acked-by: Jiri Benc <jbenc@redhat.com>


^ permalink raw reply	[flat|nested] 3+ messages in thread

* Re: [PATCH net v2] net: mpls: clear inner_protocol when the last label is popped
  2026-09-02  9:27 [PATCH net v2] net: mpls: clear inner_protocol when the last label is popped Fourie Zhang
  2026-09-03 11:17 ` Jiri Benc
@ 2026-09-04 23:10 ` patchwork-bot+netdevbpf
  1 sibling, 0 replies; 3+ messages in thread
From: patchwork-bot+netdevbpf @ 2026-09-04 23:10 UTC (permalink / raw)
  To: Fourie Zhang
  Cc: netdev, davem, kuba, pabeni, edumazet, jbenc, horms, jhs,
	xiyou.wangcong, jiri, aconole, i.maximets, dev, stable, corvus,
	fouriezhang

Hello:

This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@kernel.org>:

On Wed,  2 Sep 2026 17:27:12 +0800 you wrote:
> skb_mpls_push() records the pre-encapsulation network header once, gated
> on !skb->inner_protocol. skb_mpls_pop() never clears that record, so it
> outlives the encapsulation it describes.
> 
> Open vSwitch can then re-push MPLS onto a packet whose
> inner_network_header still points at the older, deeper offset: push a
> label, pop every label, recirculate (ovs_flow_key_update() re-derives
> key->eth.type and resets network_header, but leaves inner_*), then push
> again. ovs_fragment() trusts the record:
> 
> [...]

Here is the summary with links:
  - [net,v2] net: mpls: clear inner_protocol when the last label is popped
    https://git.kernel.org/netdev/net/c/78a86d75a70e

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html



^ permalink raw reply	[flat|nested] 3+ messages in thread

end of thread, other threads:[~2026-09-04 23:11 UTC | newest]

Thread overview: 3+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2026-09-02  9:27 [PATCH net v2] net: mpls: clear inner_protocol when the last label is popped Fourie Zhang
2026-09-03 11:17 ` Jiri Benc
2026-09-04 23:10 ` patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox