Yue Haibing
8382e7ed2d
ip6mr: Fix skb_under_panic in ip6mr_cache_report()
...
[ Upstream commit 30e0191b16e8a58e4620fa3e2839ddc7b9d4281c ]
skbuff: skb_under_panic: text:ffffffff88771f69 len:56 put:-4
head:ffff88805f86a800 data:ffff887f5f86a850 tail:0x88 end:0x2c0 dev:pim6reg
------------[ cut here ]------------
kernel BUG at net/core/skbuff.c:192!
invalid opcode: 0000 [#1 ] PREEMPT SMP KASAN
CPU: 2 PID: 22968 Comm: kworker/2:11 Not tainted 6.5.0-rc3-00044-g0a8db05b571a #236
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
Workqueue: ipv6_addrconf addrconf_dad_work
RIP: 0010:skb_panic+0x152/0x1d0
Call Trace:
<TASK>
skb_push+0xc4/0xe0
ip6mr_cache_report+0xd69/0x19b0
reg_vif_xmit+0x406/0x690
dev_hard_start_xmit+0x17e/0x6e0
__dev_queue_xmit+0x2d6a/0x3d20
vlan_dev_hard_start_xmit+0x3ab/0x5c0
dev_hard_start_xmit+0x17e/0x6e0
__dev_queue_xmit+0x2d6a/0x3d20
neigh_connected_output+0x3ed/0x570
ip6_finish_output2+0x5b5/0x1950
ip6_finish_output+0x693/0x11c0
ip6_output+0x24b/0x880
NF_HOOK.constprop.0+0xfd/0x530
ndisc_send_skb+0x9db/0x1400
ndisc_send_rs+0x12a/0x6c0
addrconf_dad_completed+0x3c9/0xea0
addrconf_dad_work+0x849/0x1420
process_one_work+0xa22/0x16e0
worker_thread+0x679/0x10c0
ret_from_fork+0x28/0x60
ret_from_fork_asm+0x11/0x20
When setup a vlan device on dev pim6reg, DAD ns packet may sent on reg_vif_xmit().
reg_vif_xmit()
ip6mr_cache_report()
skb_push(skb, -skb_network_offset(pkt));//skb_network_offset(pkt) is 4
And skb_push declared as:
void *skb_push(struct sk_buff *skb, unsigned int len);
skb->data -= len;
//0xffff88805f86a84c - 0xfffffffc = 0xffff887f5f86a850
skb->data is set to 0xffff887f5f86a850, which is invalid mem addr, lead to skb_push() fails.
Fixes: 14fb64e1f449 ("[IPV6] MROUTE: Support PIM-SM (SSM).")
Signed-off-by: Yue Haibing <yuehaibing@huawei.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-08-11 11:45:37 +02:00
..
2023-03-17 08:31:44 +01:00
2023-08-11 11:45:01 +02:00
2020-04-29 16:31:17 +02:00
2023-08-11 11:45:30 +02:00
2022-11-25 17:40:17 +01:00
2023-04-26 11:21:53 +02:00
2020-11-24 13:27:15 +01:00
2020-08-11 15:32:34 +02:00
2021-03-17 16:43:44 +01:00
2023-02-22 12:47:21 +01:00
2023-06-28 10:15:29 +02:00
2022-07-12 16:29:00 +02:00
2023-05-30 12:42:14 +01:00
2021-07-20 16:15:52 +02:00
2023-08-11 11:45:18 +02:00
2020-04-29 16:31:16 +02:00
2022-06-06 08:24:20 +02:00
2022-02-08 18:23:09 +01:00
2023-08-11 11:45:01 +02:00
2023-08-11 11:45:26 +02:00
2021-03-04 09:39:59 +01:00
2022-11-10 17:46:54 +01:00
2022-03-02 11:38:12 +01:00
2023-04-20 12:04:38 +02:00
2023-03-22 13:27:09 +01:00
2019-01-09 17:38:31 +01:00
2022-01-11 13:58:50 +01:00
2023-08-11 11:45:37 +02:00
2023-04-26 11:21:52 +02:00
2020-09-26 18:01:29 +02:00
2021-06-03 08:38:11 +02:00
2020-11-18 19:18:44 +01:00
2021-07-20 16:16:00 +02:00
2023-06-21 15:39:58 +02:00
2023-06-09 10:23:54 +02:00
2023-08-11 11:45:18 +02:00
2022-11-10 17:46:53 +01:00
2022-07-07 17:35:10 +02:00
2022-07-21 21:09:29 +02:00
2022-07-21 21:09:29 +02:00
2022-09-15 12:17:06 +02:00
2023-05-17 11:13:23 +02:00
2022-05-12 12:20:25 +02:00
2023-04-26 11:21:53 +02:00
2023-04-26 11:21:52 +02:00
2023-08-11 11:45:18 +02:00
2023-05-30 12:42:14 +01:00
2022-04-15 14:14:36 +02:00
2022-12-08 11:18:30 +01:00
2019-05-25 18:23:41 +02:00