]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
amt: make the head writable before rewriting the L2 header
authorMichael Bommarito <michael.bommarito@gmail.com>
Sat, 11 Jul 2026 15:19:34 +0000 (11:19 -0400)
committerJakub Kicinski <kuba@kernel.org>
Wed, 22 Jul 2026 14:51:42 +0000 (07:51 -0700)
amt_multicast_data_handler(), amt_membership_query_handler() and
amt_update_handler() rewrite the ethernet header of the decapsulated skb
in place (eth->h_proto, eth->h_dest and, for the query, also
eth->h_source) before handing it up the stack.  The skb head may be
shared, for example when a packet tap has cloned it on the underlay
interface, so writing through it corrupts the other reader's copy.

Call skb_cow_head() before the rewrite so the head is private.  It is
placed before the pointers into the head are (re-)derived, so a
reallocation caused by the copy is picked up by those derivations.

Fixes: cbc21dc1cfe9 ("amt: add data plane of amt interface")
Signed-off-by: Michael Bommarito <michael.bommarito@gmail.com>
Reviewed-by: Simon Horman <horms@kernel.org>
Reviewed-by: Taehee Yoo <ap420073@gmail.com>
Link: https://patch.msgid.link/20260711151934.2955226-3-michael.bommarito@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
drivers/net/amt.c

index 35e77af76bd9df812d88a3e0d149cbbee28f9a8f..b733309b866ffa35f6da0f8749922d40640a9b1c 100644 (file)
@@ -2320,6 +2320,9 @@ static bool amt_multicast_data_handler(struct amt_dev *amt, struct sk_buff *skb)
        skb_reset_mac_header(skb);
        skb_pull(skb, sizeof(*eth));
 
+       if (skb_cow_head(skb, 0))
+               return true;
+
        if (!pskb_may_pull(skb, sizeof(*iph)))
                return true;
        iph = ip_hdr(skb);
@@ -2396,6 +2399,8 @@ static bool amt_membership_query_handler(struct amt_dev *amt,
        skb_reset_network_header(skb);
        eth = eth_hdr(skb);
        ether_addr_copy(h_source, oeth->h_source);
+       if (skb_cow_head(skb, 0))
+               return true;
        if (!pskb_may_pull(skb, sizeof(*iph)))
                return true;
 
@@ -2521,6 +2526,9 @@ report:
        if (!pskb_may_pull(skb, sizeof(*iph)))
                return true;
 
+       if (skb_cow_head(skb, 0))
+               return true;
+
        iph = ip_hdr(skb);
        if (iph->version == 4) {
                if (ip_mc_check_igmp(skb)) {