From: Eric Dumazet <edumazet@kernel.org>
To: Ren Wei <weir@nebusec.ai>,
netdev@vger.kernel.org, kuba@kernel.org, jhs@mojatatu.com
Cc: andrew+netdev@lunn.ch, davem@davemloft.net, pabeni@redhat.com,
vega@nebusec.ai, bronzed_45_vested@icloud.com,
enjou1224z@gmail.com
Subject: Re: [PATCH net v4 1/1] net: loopback: reject skbs with a short linear Ethernet header
Date: Mon, 5 Oct 2026 08:14:27 +0200 [thread overview]
Message-ID: <e85fa16e-df3c-43dd-bb3a-9edca07200ea@kernel.org> (raw)
In-Reply-To: <20261005052249.1914367-2-weir@nebusec.ai>
On 10/5/26 07:22, Ren Wei wrote:
> From: Wyatt Feng <bronzed_45_vested@icloud.com>
>
> loopback_xmit() calls eth_type_trans(), which reads the Ethernet header
> from skb->data and consumes ETH_HLEN bytes. This requires at least
> ETH_HLEN bytes in the skb's linear area.
>
> An earlier transformation can leave a non-linear skb with fewer than
> ETH_HLEN bytes in the linear area, even when skb->len is at least
> ETH_HLEN. Pulling the header then makes skb->len smaller than
> skb->data_len and triggers the BUG in __skb_pull().
>
> Check skb_headlen(skb) before calling eth_type_trans(). Reject skbs
> whose linear area is too short, including those whose total length is
> less than ETH_HLEN, without attempting to pull bytes from fragments.
> Free rejected skbs, account them as TX drops and return NETDEV_TX_OK.
>
> Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> Cc: stable@vger.kernel.org
> Reported-by: Vega <vega@nebusec.ai>
> Link: https://lore.kernel.org/all/2d4e79d252a57bdad83435999dddf2c4b708dcfa.1785049236.git.bronzed_45_vested@icloud.com/
> Suggested-by: Jamal Hadi Salim <jhs@mojatatu.com>
> Assisted-by: Codex:GPT-5.4
> Signed-off-by: Wyatt Feng <bronzed_45_vested@icloud.com>
> Signed-off-by: Ren Wei <enjou1224z@gmail.com>
> ---
NACK
If if we do not fix the root cause, we will have hundreds of drivers to fix.
Stop making linux slower and slower just because you can.
next prev parent reply other threads:[~2026-10-05 6:14 UTC|newest]
Thread overview: 4+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-10-05 5:22 [PATCH net v4 0/1] net: loopback: reject skbs with a short linear Ethernet header Ren Wei
2026-10-05 5:22 ` [PATCH net v4 1/1] " Ren Wei
2026-10-05 6:14 ` Eric Dumazet [this message]
2026-10-05 20:23 ` [PATCH net v4 0/1] " Andrew Lunn
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=e85fa16e-df3c-43dd-bb3a-9edca07200ea@kernel.org \
--to=edumazet@kernel.org \
--cc=andrew+netdev@lunn.ch \
--cc=bronzed_45_vested@icloud.com \
--cc=davem@davemloft.net \
--cc=enjou1224z@gmail.com \
--cc=jhs@mojatatu.com \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=vega@nebusec.ai \
--cc=weir@nebusec.ai \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox