* [PATCH] net/tls: fix kernel panic when alloc_page failed
@ 2025-05-14 13:20 Pengtao He
2025-05-15 14:50 ` patchwork-bot+netdevbpf
0 siblings, 1 reply; 2+ messages in thread
From: Pengtao He @ 2025-05-14 13:20 UTC (permalink / raw)
To: borisp, john.fastabend, kuba, davem, edumazet, pabeni, horms
Cc: netdev, linux-kernel, Pengtao He
We cannot set frag_list to NULL pointer when alloc_page failed.
It will be used in tls_strp_check_queue_ok when the next time
tls_strp_read_sock is called.
Unable to handle kernel NULL pointer dereference
at virtual address 0000000000000028
Call trace:
tls_strp_check_rcv+0x128/0x27c
tls_strp_data_ready+0x34/0x44
tls_data_ready+0x3c/0x1f0
tcp_data_ready+0x9c/0xe4
tcp_data_queue+0xf6c/0x12d0
tcp_rcv_established+0x52c/0x798
Signed-off-by: Pengtao He <hept.hept.hept@gmail.com>
---
net/tls/tls_strp.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/tls/tls_strp.c b/net/tls/tls_strp.c
index 77e33e1e340e..65b0da6fdf6a 100644
--- a/net/tls/tls_strp.c
+++ b/net/tls/tls_strp.c
@@ -396,7 +396,6 @@ static int tls_strp_read_copy(struct tls_strparser *strp, bool qshort)
return 0;
shinfo = skb_shinfo(strp->anchor);
- shinfo->frag_list = NULL;
/* If we don't know the length go max plus page for cipher overhead */
need_spc = strp->stm.full_len ?: TLS_MAX_PAYLOAD_SIZE + PAGE_SIZE;
@@ -412,6 +411,8 @@ static int tls_strp_read_copy(struct tls_strparser *strp, bool qshort)
page, 0, 0);
}
+ shinfo->frag_list = NULL;
+
strp->copy_mode = 1;
strp->stm.offset = 0;
--
2.37.1
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH] net/tls: fix kernel panic when alloc_page failed
2025-05-14 13:20 [PATCH] net/tls: fix kernel panic when alloc_page failed Pengtao He
@ 2025-05-15 14:50 ` patchwork-bot+netdevbpf
0 siblings, 0 replies; 2+ messages in thread
From: patchwork-bot+netdevbpf @ 2025-05-15 14:50 UTC (permalink / raw)
To: Pengtao He
Cc: borisp, john.fastabend, kuba, davem, edumazet, pabeni, horms,
netdev, linux-kernel
Hello:
This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@kernel.org>:
On Wed, 14 May 2025 21:20:13 +0800 you wrote:
> We cannot set frag_list to NULL pointer when alloc_page failed.
> It will be used in tls_strp_check_queue_ok when the next time
> tls_strp_read_sock is called.
>
> Unable to handle kernel NULL pointer dereference
> at virtual address 0000000000000028
> Call trace:
> tls_strp_check_rcv+0x128/0x27c
> tls_strp_data_ready+0x34/0x44
> tls_data_ready+0x3c/0x1f0
> tcp_data_ready+0x9c/0xe4
> tcp_data_queue+0xf6c/0x12d0
> tcp_rcv_established+0x52c/0x798
>
> [...]
Here is the summary with links:
- net/tls: fix kernel panic when alloc_page failed
https://git.kernel.org/netdev/net/c/491deb9b8c4a
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2025-05-15 14:49 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-05-14 13:20 [PATCH] net/tls: fix kernel panic when alloc_page failed Pengtao He
2025-05-15 14:50 ` patchwork-bot+netdevbpf
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®