]> git.ipfire.org Git - thirdparty/linux.git/commitdiff
vsock/virtio: Move SKB allocation lower-bound check to callers
authorWill Deacon <will@kernel.org>
Thu, 17 Jul 2025 09:01:13 +0000 (10:01 +0100)
committerMichael S. Tsirkin <mst@redhat.com>
Fri, 1 Aug 2025 13:11:09 +0000 (09:11 -0400)
virtio_vsock_alloc_linear_skb() checks that the requested size is at
least big enough for the packet header (VIRTIO_VSOCK_SKB_HEADROOM).

Of the three callers of virtio_vsock_alloc_linear_skb(), only
vhost_vsock_alloc_skb() can potentially pass a packet smaller than the
header size and, as it already has a check against the maximum packet
size, extend its bounds checking to consider the minimum packet size
and remove the check from virtio_vsock_alloc_linear_skb().

Reviewed-by: Stefano Garzarella <sgarzare@redhat.com>
Signed-off-by: Will Deacon <will@kernel.org>
Message-Id: <20250717090116.11987-7-will@kernel.org>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
drivers/vhost/vsock.c
include/linux/virtio_vsock.h

index 1ad96613680effdb34a526480469502127b37cd4..24b7547b05a6c29d26146f026d1ef099931d52b8 100644 (file)
@@ -344,7 +344,8 @@ vhost_vsock_alloc_skb(struct vhost_virtqueue *vq,
 
        len = iov_length(vq->iov, out);
 
-       if (len > VIRTIO_VSOCK_MAX_PKT_BUF_SIZE + VIRTIO_VSOCK_SKB_HEADROOM)
+       if (len < VIRTIO_VSOCK_SKB_HEADROOM ||
+           len > VIRTIO_VSOCK_MAX_PKT_BUF_SIZE + VIRTIO_VSOCK_SKB_HEADROOM)
                return NULL;
 
        /* len contains both payload and hdr */
index 4504ea29ff8241f01960125aa3e4611fd491c129..36dd0cd553688861c1ab366d97b3776ccf4b4883 100644 (file)
@@ -57,9 +57,6 @@ virtio_vsock_alloc_linear_skb(unsigned int size, gfp_t mask)
 {
        struct sk_buff *skb;
 
-       if (size < VIRTIO_VSOCK_SKB_HEADROOM)
-               return NULL;
-
        skb = alloc_skb(size, mask);
        if (!skb)
                return NULL;