mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
From: "Nicolas S. Dade" <ndade@adsl-63-197-69-248.dsl.snfc21.pacbell.net>
To: linux-kernel@vger.kernel.org
Subject: BUG in 2.2.22 skb_realloc_headroom()
Date: Tue, 29 Oct 2002 21:19:45 -0800	[thread overview]
Message-ID: <20021029211945.A17657@ipx.esperanza> (raw)

[-- Attachment #1: Type: text/plain, Size: 969 bytes --]

Kernel: 2.2.22
File: net/core/skbuff.c

skb_realloc_headroom() panics when new headroom is smaller
than existing headroom. Specifically the skb_put() fails
and calls skb_over_panic() because the new buffer is too
small.

When skb_realloc_headroom() is called from skb_cow(), it
can be called when the existing headroom size is >=
the desired headroom but the packet in question is cloned.

Then skb_realloc_headroom() allocates

 skb_alloc( skb->truesize + new_headroom - old_headroom )

but if the old_headroom > new_headroom then the resulting
buffer is too small to hold new_headroom + skb->len.

I found this when running tethereal (thus causing the packets
to be cloned for libpcap) and passing data from an acenic,
which allocates 48 bytes of headroom in its skbuff's, to
another ethernet device, which needs only 14 (rounded to 16)
bytes of headroom for the ethernet header.

Here's how I think it should be fixed:

-- 
-- Nicolas Dade    http://nsd.dyndns.org/

[-- Attachment #2: skb_realloc_headroom.diff --]
[-- Type: text/plain, Size: 750 bytes --]

--- linux-2.2.22/net/core/skbuff.c.orig	Tue Oct 29 21:13:24 2002
+++ linux-2.2.22/net/core/skbuff.c	Tue Oct 29 21:15:14 2002
@@ -7,6 +7,7 @@
  *	Version:	$Id: skbuff.c,v 1.55 1999/02/23 08:12:27 davem Exp $
  *
  *	Fixes:	
+ *              Nicolas Dade    :       Fixed skb_realloc_headroom to smaller headroom
  *		Alan Cox	:	Fixed the worst of the load balancer bugs.
  *		Dave Platt	:	Interrupt stacking fix.
  *	Richard Kooijman	:	Timestamp fixes.
@@ -316,13 +317,12 @@
 {
 	struct sk_buff *n;
 	unsigned long offset;
-	int headroom = skb_headroom(skb);
 
 	/*
 	 *	Allocate the copy buffer
 	 */
  	 
-	n=alloc_skb(skb->truesize+newheadroom-headroom, GFP_ATOMIC);
+	n=alloc_skb(skb->len+newheadroom, GFP_ATOMIC);
 	if(n==NULL)
 		return NULL;
 

             reply	other threads:[~2002-10-30  5:18 UTC|newest]

Thread overview: 3+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2002-10-30  5:19 Nicolas S. Dade [this message]
2002-10-30 10:36 ` James Morris
2002-10-30 10:51   ` Nicolas S. Dade

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20021029211945.A17657@ipx.esperanza \
    --to=ndade@adsl-63-197-69-248.dsl.snfc21.pacbell.net \
    --cc=linux-kernel@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®