Yue Haibing
1683124129
ip6mr: Fix skb_under_panic in ip6mr_cache_report()
...
[ Upstream commit 30e0191b16e8a58e4620fa3e2839ddc7b9d4281c ]
skbuff: skb_under_panic: text:ffffffff88771f69 len:56 put:-4
head:ffff88805f86a800 data:ffff887f5f86a850 tail:0x88 end:0x2c0 dev:pim6reg
------------[ cut here ]------------
kernel BUG at net/core/skbuff.c:192!
invalid opcode: 0000 [#1 ] PREEMPT SMP KASAN
CPU: 2 PID: 22968 Comm: kworker/2:11 Not tainted 6.5.0-rc3-00044-g0a8db05b571a #236
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
Workqueue: ipv6_addrconf addrconf_dad_work
RIP: 0010:skb_panic+0x152/0x1d0
Call Trace:
<TASK>
skb_push+0xc4/0xe0
ip6mr_cache_report+0xd69/0x19b0
reg_vif_xmit+0x406/0x690
dev_hard_start_xmit+0x17e/0x6e0
__dev_queue_xmit+0x2d6a/0x3d20
vlan_dev_hard_start_xmit+0x3ab/0x5c0
dev_hard_start_xmit+0x17e/0x6e0
__dev_queue_xmit+0x2d6a/0x3d20
neigh_connected_output+0x3ed/0x570
ip6_finish_output2+0x5b5/0x1950
ip6_finish_output+0x693/0x11c0
ip6_output+0x24b/0x880
NF_HOOK.constprop.0+0xfd/0x530
ndisc_send_skb+0x9db/0x1400
ndisc_send_rs+0x12a/0x6c0
addrconf_dad_completed+0x3c9/0xea0
addrconf_dad_work+0x849/0x1420
process_one_work+0xa22/0x16e0
worker_thread+0x679/0x10c0
ret_from_fork+0x28/0x60
ret_from_fork_asm+0x11/0x20
When setup a vlan device on dev pim6reg, DAD ns packet may sent on reg_vif_xmit().
reg_vif_xmit()
ip6mr_cache_report()
skb_push(skb, -skb_network_offset(pkt));//skb_network_offset(pkt) is 4
And skb_push declared as:
void *skb_push(struct sk_buff *skb, unsigned int len);
skb->data -= len;
//0xffff88805f86a84c - 0xfffffffc = 0xffff887f5f86a850
skb->data is set to 0xffff887f5f86a850, which is invalid mem addr, lead to skb_push() fails.
Fixes: 14fb64e1f449 ("[IPV6] MROUTE: Support PIM-SM (SSM).")
Signed-off-by: Yue Haibing <yuehaibing@huawei.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-08-11 11:57:50 +02:00
..
2021-09-15 09:50:34 +02:00
2023-04-20 12:10:25 +02:00
2023-01-14 10:16:18 +01:00
2023-05-30 12:57:53 +01:00
2021-04-07 15:00:08 +02:00
2023-06-09 10:30:12 +02:00
2022-06-22 14:13:17 +02:00
2023-06-21 15:45:40 +02:00
2023-06-14 11:09:52 +02:00
2023-01-14 10:15:31 +01:00
2021-07-14 16:56:29 +02:00
2023-07-27 08:44:39 +02:00
2023-03-17 08:45:11 +01:00
2023-07-27 08:44:35 +02:00
2022-05-25 09:17:56 +02:00
2023-08-11 11:57:49 +02:00
2023-08-11 11:57:50 +02:00
2023-04-26 11:27:42 +02:00
2023-06-21 15:45:38 +02:00
2023-07-27 08:44:10 +02:00
2023-01-24 07:19:55 +01:00
2023-04-05 11:23:52 +02:00
2022-11-03 23:57:51 +09:00
2023-07-27 08:44:43 +02:00
2023-08-11 11:57:50 +02:00
2023-03-22 13:30:00 +01:00
2022-11-25 17:45:56 +01:00
2023-05-30 12:57:51 +01:00
2023-04-26 11:27:41 +02:00
2022-04-27 13:53:50 +02:00
2021-02-10 09:29:14 +01:00
2023-07-27 08:44:40 +02:00
2023-05-30 12:57:53 +01:00
2022-12-14 11:32:01 +01:00
2023-02-22 12:55:58 +01:00
2023-04-26 11:27:41 +02:00
2023-05-17 11:48:10 +02:00
2023-08-11 11:57:36 +02:00
2022-04-13 21:01:00 +02:00
2023-07-27 08:43:43 +02:00
2023-06-09 10:30:05 +02:00
2023-07-27 08:43:43 +02:00
2023-05-30 12:57:52 +01:00
2023-02-22 12:55:57 +01:00
2023-06-09 10:30:05 +02:00
2022-01-11 15:25:01 +01:00
2021-03-07 12:34:07 +01:00
2023-04-20 12:10:26 +02:00
2023-03-11 16:39:26 +01:00
2023-02-22 12:55:53 +01:00
2023-05-17 11:48:11 +02:00
2023-08-11 11:57:49 +02:00
2023-07-27 08:44:08 +02:00
2023-06-14 11:09:39 +02:00
2021-11-18 14:04:27 +01:00
2023-07-27 08:44:02 +02:00
2023-08-11 11:57:37 +02:00
2023-05-30 12:57:46 +01:00
2023-08-11 11:57:49 +02:00
2023-05-30 12:57:52 +01:00
2023-08-11 11:57:47 +02:00
2023-02-15 17:22:15 +01:00
2023-07-27 08:44:09 +02:00
2023-06-28 10:28:10 +02:00
2021-06-18 10:00:06 +02:00
2023-06-21 15:45:38 +02:00
2023-06-21 15:45:38 +02:00
2023-07-27 08:43:37 +02:00