Yue Haibing
1bb54a21f4
ip6mr: Fix skb_under_panic in ip6mr_cache_report()
...
[ Upstream commit 30e0191b16e8a58e4620fa3e2839ddc7b9d4281c ]
skbuff: skb_under_panic: text:ffffffff88771f69 len:56 put:-4
head:ffff88805f86a800 data:ffff887f5f86a850 tail:0x88 end:0x2c0 dev:pim6reg
------------[ cut here ]------------
kernel BUG at net/core/skbuff.c:192!
invalid opcode: 0000 [#1 ] PREEMPT SMP KASAN
CPU: 2 PID: 22968 Comm: kworker/2:11 Not tainted 6.5.0-rc3-00044-g0a8db05b571a #236
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
Workqueue: ipv6_addrconf addrconf_dad_work
RIP: 0010:skb_panic+0x152/0x1d0
Call Trace:
<TASK>
skb_push+0xc4/0xe0
ip6mr_cache_report+0xd69/0x19b0
reg_vif_xmit+0x406/0x690
dev_hard_start_xmit+0x17e/0x6e0
__dev_queue_xmit+0x2d6a/0x3d20
vlan_dev_hard_start_xmit+0x3ab/0x5c0
dev_hard_start_xmit+0x17e/0x6e0
__dev_queue_xmit+0x2d6a/0x3d20
neigh_connected_output+0x3ed/0x570
ip6_finish_output2+0x5b5/0x1950
ip6_finish_output+0x693/0x11c0
ip6_output+0x24b/0x880
NF_HOOK.constprop.0+0xfd/0x530
ndisc_send_skb+0x9db/0x1400
ndisc_send_rs+0x12a/0x6c0
addrconf_dad_completed+0x3c9/0xea0
addrconf_dad_work+0x849/0x1420
process_one_work+0xa22/0x16e0
worker_thread+0x679/0x10c0
ret_from_fork+0x28/0x60
ret_from_fork_asm+0x11/0x20
When setup a vlan device on dev pim6reg, DAD ns packet may sent on reg_vif_xmit().
reg_vif_xmit()
ip6mr_cache_report()
skb_push(skb, -skb_network_offset(pkt));//skb_network_offset(pkt) is 4
And skb_push declared as:
void *skb_push(struct sk_buff *skb, unsigned int len);
skb->data -= len;
//0xffff88805f86a84c - 0xfffffffc = 0xffff887f5f86a850
skb->data is set to 0xffff887f5f86a850, which is invalid mem addr, lead to skb_push() fails.
Fixes: 14fb64e1f449 ("[IPV6] MROUTE: Support PIM-SM (SSM).")
Signed-off-by: Yue Haibing <yuehaibing@huawei.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-08-11 15:13:53 +02:00
..
2023-03-17 08:48:54 +01:00
2023-03-17 08:48:55 +01:00
2023-08-03 10:22:34 +02:00
2022-11-16 09:58:18 +01:00
2023-04-26 13:51:54 +02:00
2021-06-11 14:48:50 +02:00
2023-02-22 12:57:09 +01:00
2023-06-28 10:29:46 +02:00
2022-04-27 14:38:52 +02:00
2023-05-30 13:55:31 +01:00
2023-06-14 11:13:02 +02:00
2021-12-08 09:04:43 +01:00
2023-07-23 13:47:41 +02:00
2022-08-17 14:23:36 +02:00
2021-10-12 11:49:49 +01:00
2021-10-12 11:49:49 +01:00
2022-02-01 17:27:09 +01:00
2022-02-23 12:03:10 +01:00
2023-07-27 08:47:01 +02:00
2022-11-10 18:15:38 +01:00
2022-03-02 11:47:56 +01:00
2023-04-13 16:48:18 +02:00
2023-03-22 13:31:26 +01:00
2022-01-11 15:35:17 +01:00
2023-08-11 15:13:53 +02:00
2021-06-11 14:48:50 +02:00
2023-04-26 13:51:54 +02:00
2021-07-21 08:14:33 -07:00
2021-07-21 08:14:33 -07:00
2021-04-27 14:02:06 -07:00
2022-08-03 12:03:51 +02:00
2021-06-11 14:48:50 +02:00
2022-08-25 11:40:24 +02:00
2022-05-09 09:14:41 +02:00
2021-05-31 22:12:08 -07:00
2023-06-21 15:59:16 +02:00
2023-06-05 09:21:26 +02:00
2021-05-21 15:02:25 -07:00
2023-03-11 13:57:28 +01:00
2023-04-26 13:51:49 +02:00
2022-07-07 17:53:26 +02:00
2022-07-21 21:24:30 +02:00
2022-07-21 21:24:30 +02:00
2022-09-15 11:30:06 +02:00
2023-05-17 11:50:16 +02:00
2022-07-29 17:25:18 +02:00
2021-07-21 08:14:33 -07:00
2023-07-27 08:47:01 +02:00
2023-04-26 13:51:54 +02:00
2023-07-23 13:47:41 +02:00
2023-05-30 13:55:31 +01:00
2023-06-28 10:29:46 +02:00
2022-04-08 14:22:46 +02:00
2022-12-02 17:41:06 +01:00
2021-06-09 09:38:52 +02:00