]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
xsk: tighten UMEM headroom validation to account for tailroom and min frame
authorMaciej Fijalkowski <maciej.fijalkowski@intel.com>
Thu, 2 Apr 2026 15:49:51 +0000 (17:49 +0200)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Wed, 22 Apr 2026 11:30:39 +0000 (13:30 +0200)
[ Upstream commit a315e022a72d95ef5f1d4e58e903cb492b0ad931 ]

The current headroom validation in xdp_umem_reg() could leave us with
insufficient space dedicated to even receive minimum-sized ethernet
frame. Furthermore if multi-buffer would come to play then
skb_shared_info stored at the end of XSK frame would be corrupted.

HW typically works with 128-aligned sizes so let us provide this value
as bare minimum.

Multi-buffer setting is known later in the configuration process so
besides accounting for 128 bytes, let us also take care of tailroom space
upfront.

Reviewed-by: Björn Töpel <bjorn@kernel.org>
Acked-by: Stanislav Fomichev <sdf@fomichev.me>
Fixes: 99e3a236dd43 ("xsk: Add missing check on user supplied headroom size")
Signed-off-by: Maciej Fijalkowski <maciej.fijalkowski@intel.com>
Link: https://patch.msgid.link/20260402154958.562179-2-maciej.fijalkowski@intel.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Signed-off-by: Sasha Levin <sashal@kernel.org>
net/xdp/xdp_umem.c

index 9f76ca591d54fb5cd69be6307ce15792271010aa..9ec7bd948acc74593632a197de2c057ffd5c9b9a 100644 (file)
@@ -202,7 +202,8 @@ static int xdp_umem_reg(struct xdp_umem *umem, struct xdp_umem_reg *mr)
        if (!unaligned_chunks && chunks_rem)
                return -EINVAL;
 
-       if (headroom >= chunk_size - XDP_PACKET_HEADROOM)
+       if (headroom > chunk_size - XDP_PACKET_HEADROOM -
+                      SKB_DATA_ALIGN(sizeof(struct skb_shared_info)) - 128)
                return -EINVAL;
 
        if (mr->flags & XDP_UMEM_TX_METADATA_LEN) {