Steffen Klassert ebe48d368e esp: Fix possible buffer overflow in ESP transformation
The maximum message size that can be send is bigger than
the  maximum site that skb_page_frag_refill can allocate.
So it is possible to write beyond the allocated buffer.

Fix this by doing a fallback to COW in that case.

v2:

Avoid get get_order() costs as suggested by Linus Torvalds.

Fixes: cac2661c53f3 ("esp4: Avoid skb_cow_data whenever possible")
Fixes: 03e2a30f6a27 ("esp6: Avoid skb_cow_data whenever possible")
Reported-by: valis <sec@valis.email>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
2022-03-07 13:14:03 +01:00
..
2022-01-12 11:27:57 -08:00
2022-01-23 06:20:44 +02:00
2022-02-07 17:42:44 +01:00
2022-01-16 16:15:14 +02:00
2022-01-10 19:06:09 -08:00
2022-02-01 16:52:54 +01:00
2022-01-28 19:30:35 +02:00