]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
vxlan: re-fetch eth header after route_shortcircuit()
authorEric Dumazet <edumazet@google.com>
Thu, 23 Jul 2026 14:42:45 +0000 (14:42 +0000)
committerJakub Kicinski <kuba@kernel.org>
Mon, 27 Jul 2026 22:15:13 +0000 (15:15 -0700)
Before route_shortcircuit(), the eth header pointer is cached from eth_hdr(skb).

Inside route_shortcircuit(), pskb_may_pull() can be called, which may
reallocate skb->head.

In this case, returning to vxlan_xmit() leaves the cached eth pointer pointing to
freed memory, leading to a use-after-free when dereferencing eth->h_dest.

Fix this by updating eth = eth_hdr(skb) after calling route_shortcircuit().

Fixes: ae8840825605 ("VXLAN: Allow L2 redirection with L3 switching")
Cc: stable@vger.kernel.org
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reviewed-by: Vadim Fedorenko <vadim.fedorenko@linux.dev>
Link: https://patch.msgid.link/20260723144249.759100-2-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
drivers/net/vxlan/vxlan_core.c

index d834a4865aecc7f39fc01cde779a5acd5d0ddc1c..a05654a55bd605f7fb0141bb80806435b020ef94 100644 (file)
@@ -2796,6 +2796,7 @@ static netdev_tx_t vxlan_xmit(struct sk_buff *skb, struct net_device *dev)
            (ntohs(eth->h_proto) == ETH_P_IP ||
             ntohs(eth->h_proto) == ETH_P_IPV6)) {
                did_rsc = route_shortcircuit(dev, skb);
+               eth = eth_hdr(skb);
                if (did_rsc)
                        f = vxlan_find_mac_tx(vxlan, eth->h_dest, vni);
        }