提交 d26ed6b0 编写于 作者: F Friedemann Gerold 提交者: David S. Miller

net: aquantia: memory corruption on jumbo frames

This patch fixes skb_shared area, which will be corrupted
upon reception of 4K jumbo packets.

Originally build_skb usage purpose was to reuse page for skb to eliminate
needs of extra fragments. But that logic does not take into account that
skb_shared_info should be reserved at the end of skb data area.

In case packet data consumes all the page (4K), skb_shinfo location
overflows the page. As a consequence, __build_skb zeroed shinfo data above
the allocated page, corrupting next page.

The issue is rarely seen in real life because jumbo are normally larger
than 4K and that causes another code path to trigger.
But it 100% reproducible with simple scapy packet, like:

    sendp(IP(dst="192.168.100.3") / TCP(dport=443) \
          / Raw(RandString(size=(4096-40))), iface="enp1s0")

Fixes: 018423e9 ("net: ethernet: aquantia: Add ring support code")
Reported-by: NFriedemann Gerold <f.gerold@b-c-s.de>
Reported-by: NMichael Rauch <michael@rauch.be>
Signed-off-by: NFriedemann Gerold <f.gerold@b-c-s.de>
Tested-by: NNikita Danilov <nikita.danilov@aquantia.com>
Signed-off-by: NIgor Russkikh <igor.russkikh@aquantia.com>
Signed-off-by: NDavid S. Miller <davem@davemloft.net>
上级 841dfa43
...@@ -225,9 +225,10 @@ int aq_ring_rx_clean(struct aq_ring_s *self, ...@@ -225,9 +225,10 @@ int aq_ring_rx_clean(struct aq_ring_s *self,
} }
/* for single fragment packets use build_skb() */ /* for single fragment packets use build_skb() */
if (buff->is_eop) { if (buff->is_eop &&
buff->len <= AQ_CFG_RX_FRAME_MAX - AQ_SKB_ALIGN) {
skb = build_skb(page_address(buff->page), skb = build_skb(page_address(buff->page),
buff->len + AQ_SKB_ALIGN); AQ_CFG_RX_FRAME_MAX);
if (unlikely(!skb)) { if (unlikely(!skb)) {
err = -ENOMEM; err = -ENOMEM;
goto err_exit; goto err_exit;
...@@ -247,18 +248,21 @@ int aq_ring_rx_clean(struct aq_ring_s *self, ...@@ -247,18 +248,21 @@ int aq_ring_rx_clean(struct aq_ring_s *self,
buff->len - ETH_HLEN, buff->len - ETH_HLEN,
SKB_TRUESIZE(buff->len - ETH_HLEN)); SKB_TRUESIZE(buff->len - ETH_HLEN));
for (i = 1U, next_ = buff->next, if (!buff->is_eop) {
buff_ = &self->buff_ring[next_]; true; for (i = 1U, next_ = buff->next,
next_ = buff_->next, buff_ = &self->buff_ring[next_];
buff_ = &self->buff_ring[next_], ++i) { true; next_ = buff_->next,
skb_add_rx_frag(skb, i, buff_->page, 0, buff_ = &self->buff_ring[next_], ++i) {
buff_->len, skb_add_rx_frag(skb, i,
SKB_TRUESIZE(buff->len - buff_->page, 0,
ETH_HLEN)); buff_->len,
buff_->is_cleaned = 1; SKB_TRUESIZE(buff->len -
ETH_HLEN));
if (buff_->is_eop) buff_->is_cleaned = 1;
break;
if (buff_->is_eop)
break;
}
} }
} }
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册