mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net] net: skbuff: don't leave stale bytes in skb_copy_and_csum_bits()
@ 2026-10-07 17:29 Josef Bacik
  2026-10-07 17:34 ` netdev-bot+sinfo
                   ` (3 more replies)
  0 siblings, 4 replies; 6+ messages in thread
From: Josef Bacik @ 2026-10-07 17:29 UTC (permalink / raw)
  To: David S. Miller, Eric Dumazet, Jakub Kicinski, Paolo Abeni,
	Simon Horman, Willem de Bruijn, Kaiyuan Zhang, Mina Almasry
  Cc: netdev, linux-kernel, stable, Josef Bacik

When skb_copy_and_csum_bits() reaches unreadable frags it returns 0
after copying only the linear part, and the rest of the caller's buffer
is left as it was.  The callers copy into a buffer that is about to go
out on the wire: an ICMP error quoting the offending packet, or a
driver's TX bounce buffer in skb_copy_and_csum_dev().  Neither buffer
is zeroed beforehand, so whatever was in memory there gets sent.

Zero the part of the buffer we didn't fill.  The checksum usually
won't match the data any more, so the receiver will usually drop the
packet, but either way it no longer carries anything it shouldn't.
Only zero for a positive @len, a negative one from a broken caller must
not turn into a huge memset().

Fixes: 65249feb6b3d ("net: add support for skbs with unreadable frags")
Cc: stable@vger.kernel.org
Assisted-by: LLM
Signed-off-by: Josef Bacik <josef@toxicpanda.com>
---
This was patch 1 of the skbuff BUG_ON() series; Willem asked for it to go
to net on its own:
https://lore.kernel.org/r/willemdebruijn.kernel.235bf1cecf85f@gmail.com

Tested on net with a module that marks a nonlinear skb unreadable: the
part of the buffer past the linear data is zeroed, and a negative @len
leaves the buffer alone.

Thanks,
Josef
---
 net/core/skbuff.c | 6 +++++-
 1 file changed, 5 insertions(+), 1 deletion(-)

diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 4aea06d5167d..41beaf625421 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -3633,8 +3633,12 @@ __wsum skb_copy_and_csum_bits(const struct sk_buff *skb, int offset,
 		pos	= copy;
 	}
 
-	if (!skb_frags_readable(skb))
+	if (!skb_frags_readable(skb)) {
+		/* Don't hand the caller a buffer with stale bytes in it. */
+		if (len > 0)
+			memset(to, 0, len);
 		return 0;
+	}
 
 	for (i = 0; i < skb_shinfo(skb)->nr_frags; i++) {
 		int end;

---
base-commit: 23609bce9e1de525d1d0e73fc68c6e7971d0b49e
change-id: 20261007-b4-skb-copy-csum-stale-bytes-4bf7b713258c


^ permalink raw reply	[flat|nested] 6+ messages in thread

end of thread, other threads:[~2026-10-08 18:40 UTC | newest]

Thread overview: 6+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-07 17:29 [PATCH net] net: skbuff: don't leave stale bytes in skb_copy_and_csum_bits() Josef Bacik
2026-10-07 17:34 ` netdev-bot+sinfo
2026-10-07 18:25   ` Josef Bacik
2026-10-07 18:13 ` Mina Almasry
2026-10-08 17:59 ` netdev-bot+sashiko
2026-10-08 18:40 ` patchwork-bot+netdevbpf

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®