]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
xdp: reject clones that overrun skb_shared_info tailroom
authorZhiling Zou <zhilinz@nebusec.ai>
Mon, 3 Aug 2026 12:15:32 +0000 (20:15 +0800)
committerJakub Kicinski <kuba@kernel.org>
Thu, 6 Aug 2026 15:49:19 +0000 (08:49 -0700)
xdpf_clone() clones broadcast copies into a single page and sets
frame_sz to PAGE_SIZE. __xdp_build_skb_from_frame() later treats that
page like a normal XDP frame and expects the usual skb_shared_info
tailroom at the end of the buffer.

The current check only rejects frames whose linear xdp_frame header,
headroom, and packet data exceed PAGE_SIZE. A source frame backed by a
larger allocation can still satisfy that check while extending into the
clone's required shared-info area. When such a clone is converted back
into an skb, build_skb_around() places skb_shared_info over live packet
bytes and later writes can corrupt XDP return metadata.

Reject clones unless their linear area fits inside
SKB_WITH_OVERHEAD(PAGE_SIZE), matching the tailroom requirement already
enforced by the XDP-to-skb conversion path.

Fixes: e624d4ed4aa8 ("xdp: Extend xdp_redirect_map with broadcast support")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Link: https://patch.msgid.link/6b2afef5d1738763c6965e8e466eb16e43e4f956.1785757386.git.zhilinz@nebusec.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/core/xdp.c

index 9890a30584ba7b08b246dacb984b639908f16242..0194e69da339a501ca2c1f46a282b603810e1bbf 100644 (file)
@@ -871,7 +871,7 @@ struct xdp_frame *xdpf_clone(struct xdp_frame *xdpf)
        headroom = xdpf->headroom + sizeof(*xdpf);
        totalsize = headroom + xdpf->len;
 
-       if (unlikely(totalsize > PAGE_SIZE))
+       if (unlikely(totalsize > SKB_WITH_OVERHEAD(PAGE_SIZE)))
                return NULL;
        page = dev_alloc_page();
        if (!page)