]> git.ipfire.org Git - thirdparty/linux.git/commit
usbnet: cap max_mtu for drivers without bind callback
authorLaurent Vivier <lvivier@redhat.com>
Fri, 31 Jul 2026 09:27:11 +0000 (11:27 +0200)
committerJakub Kicinski <kuba@kernel.org>
Wed, 5 Aug 2026 01:17:20 +0000 (18:17 -0700)
commit1505b2cb6ae1c7e8ac0c6e4590a204ffc3ab2b24
tree820e46281e3d26410c7a2e2c63cc81e296b5c7d5
parent2cbd8a4e5e09aa232a1f8d56ce3d070b18ab2b10
usbnet: cap max_mtu for drivers without bind callback

usbnet_probe() initializes max_mtu to ETH_MAX_MTU and only caps it
inside the if (info->bind) block. Drivers without a bind callback
never enter this block, so max_mtu stays at ETH_MAX_MTU.

QEMU's usb-net device (0x0525/0xa4a2) is claimed by the cdc_subset
driver which has no bind callback. The guest accepts any MTU from DHCP
(e.g. 65520 from passt), leading to TCP segments that exceed the
device's 2048-byte receive buffer and are silently dropped.

Initialize max_mtu to net->mtu at probe time and update it inside
the bind block.

Fixes: f77f0aee4da4 ("net: use core MTU range checking in USB NIC drivers")
Cc: jarod@redhat.com
Cc: stable@vger.kernel.org
Link: https://gitlab.com/qemu-project/qemu/-/issues/3268
Link: https://bugs.passt.top/show_bug.cgi?id=189
Signed-off-by: Laurent Vivier <lvivier@redhat.com>
Link: https://patch.msgid.link/20260731092711.857684-1-lvivier@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
drivers/net/usb/usbnet.c