Skip to content

Commit d34c304

Browse files
zhengchaoshaogregkh
authored andcommitted
ip_vti: fix potential slab-use-after-free in decode_session6
[ Upstream commit 6018a26 ] When ip_vti device is set to the qdisc of the sfb type, the cb field of the sent skb may be modified during enqueuing. Then, slab-use-after-free may occur when ip_vti device sends IPv6 packets. As commit f855691 ("xfrm6: Fix the nexthdr offset in _decode_session6.") showed, xfrm_decode_session was originally intended only for the receive path. IP6CB(skb)->nhoff is not set during transmission. Therefore, set the cb field in the skb to 0 before sending packets. Fixes: f855691 ("xfrm6: Fix the nexthdr offset in _decode_session6.") Signed-off-by: Zhengchao Shao <[email protected]> Signed-off-by: Steffen Klassert <[email protected]> Signed-off-by: Sasha Levin <[email protected]>
1 parent eb47e61 commit d34c304

File tree

1 file changed

+2
-2
lines changed

1 file changed

+2
-2
lines changed

net/ipv4/ip_vti.c

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -314,12 +314,12 @@ static netdev_tx_t vti_tunnel_xmit(struct sk_buff *skb, struct net_device *dev)
314314

315315
switch (skb->protocol) {
316316
case htons(ETH_P_IP):
317-
xfrm_decode_session(skb, &fl, AF_INET);
318317
memset(IPCB(skb), 0, sizeof(*IPCB(skb)));
318+
xfrm_decode_session(skb, &fl, AF_INET);
319319
break;
320320
case htons(ETH_P_IPV6):
321-
xfrm_decode_session(skb, &fl, AF_INET6);
322321
memset(IP6CB(skb), 0, sizeof(*IP6CB(skb)));
322+
xfrm_decode_session(skb, &fl, AF_INET6);
323323
break;
324324
default:
325325
goto tx_err;

0 commit comments

Comments
 (0)