]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
bareudp: Pull inner IP header in bareudp_udp_encap_recv().
authorGuillaume Nault <gnault@redhat.com>
Wed, 11 Sep 2024 09:20:58 +0000 (11:20 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 4 Oct 2024 14:28:58 +0000 (16:28 +0200)
[ Upstream commit 45fa29c85117170b0508790f878b13ec6593c888 ]

Bareudp reads the inner IP header to get the ECN value. Therefore, it
needs to ensure that it's part of the skb's linear data.

This is similar to the vxlan and geneve fixes for that same problem:
  * commit f7789419137b ("vxlan: Pull inner IP header in vxlan_rcv().")
  * commit 1ca1ba465e55 ("geneve: make sure to pull inner header in
    geneve_rx()")

Fixes: 571912c69f0e ("net: UDP tunnel encapsulation module for tunnelling different protocols like MPLS, IP, NSH etc.")
Signed-off-by: Guillaume Nault <gnault@redhat.com>
Reviewed-by: Willem de Bruijn <willemb@google.com>
Link: https://patch.msgid.link/5205940067c40218a70fbb888080466b2fc288db.1726046181.git.gnault@redhat.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
drivers/net/bareudp.c

index 277493e41b0723e7b9f92b4cf7c23d43df501fcd..d0759d8bf73052749ed86e780e34c3c77e1cc5df 100644 (file)
@@ -67,6 +67,7 @@ static int bareudp_udp_encap_recv(struct sock *sk, struct sk_buff *skb)
        __be16 proto;
        void *oiph;
        int err;
+       int nh;
 
        bareudp = rcu_dereference_sk_user_data(sk);
        if (!bareudp)
@@ -144,10 +145,25 @@ static int bareudp_udp_encap_recv(struct sock *sk, struct sk_buff *skb)
        }
        skb_dst_set(skb, &tun_dst->dst);
        skb->dev = bareudp->dev;
-       oiph = skb_network_header(skb);
-       skb_reset_network_header(skb);
        skb_reset_mac_header(skb);
 
+       /* Save offset of outer header relative to skb->head,
+        * because we are going to reset the network header to the inner header
+        * and might change skb->head.
+        */
+       nh = skb_network_header(skb) - skb->head;
+
+       skb_reset_network_header(skb);
+
+       if (!pskb_inet_may_pull(skb)) {
+               DEV_STATS_INC(bareudp->dev, rx_length_errors);
+               DEV_STATS_INC(bareudp->dev, rx_errors);
+               goto drop;
+       }
+
+       /* Get the outer header. */
+       oiph = skb->head + nh;
+
        if (!ipv6_mod_enabled() || family == AF_INET)
                err = IP_ECN_decapsulate(oiph, skb);
        else