From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from mail-qv1-f51.google.com (mail-qv1-f51.google.com [209.85.219.51]) (using TLSv1.2 with cipher ECDHE-RSA-AES128-GCM-SHA256 (128/128 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id 4662443CED8 for ; Tue, 9 Jun 2026 18:56:51 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=209.85.219.51 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781031413; cv=none; b=q6DH2zmvD8xqRqDoNhVG3z9WSbtCVgq4CeK2zEYldnn1XnCyOD9Dlcl85ighrmbSnVmFlNJBlTpWDA9Q+Zm2LQYQmvHMdQjETxXqEn9bVzMc/7hH0GwSAIBUxaYXprMLwVRTU0uNoucTicb2W0BPrWJVaP/Ezmoy0QNhtn2gJh4= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1781031413; c=relaxed/simple; bh=HJCGm0COA5ItiBybYQGy5woQjXOj1c/FVQ+aq0Bzo8I=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=GDcXD4NplE0RSNZYLHub5AvgXocB/dH51NfuhcTmZpXd9vAMRPxS1aIhsCT4yzW2N1gkIs0gCQmZASHPbPEh4tF78qFIHJHYwum2RQx2sqbAdMf92BvlWq2H+Lu93SIsZ5czvLXHxfuAs6o0V3bGi1HMEGf3cTyTA4mYJQSonto= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com; spf=pass smtp.mailfrom=trailofbits.com; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b=bAMCUPGe; arc=none smtp.client-ip=209.85.219.51 Authentication-Results: smtp.subspace.kernel.org; dmarc=pass (p=reject dis=none) header.from=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; spf=pass smtp.mailfrom=trailofbits.com Authentication-Results: smtp.subspace.kernel.org; dkim=pass (2048-bit key) header.d=trailofbits.com header.i=@trailofbits.com header.b="bAMCUPGe" Received: by mail-qv1-f51.google.com with SMTP id 6a1803df08f44-8cceaa6f75bso88508176d6.0 for ; Tue, 09 Jun 2026 11:56:51 -0700 (PDT) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=trailofbits.com; s=google; t=1781031410; x=1781636210; darn=vger.kernel.org; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:from:to:cc:subject:date :message-id:reply-to; bh=16iV7RIIpsvJlA2HjI7+KG5mxLD2wZSYZrTwJS1TsvY=; b=bAMCUPGeCZaCNUZuI1s+oTJHWQHCcor5xmNLap8cSrfkfhjFL66Uqzz00L7LPSZSdv sR0kTZl+mDjwkNKqvq3GsRzTrPBJ+GT3wxK8VTyuPll7Xv+gf7HqNFyuxh10QIQnkaTW I82iOhwIQRc+TX6tRdUMB4I28BA2vXgjnJefipkC7VSwKH4Jxz/jnitzNoyRTPA7xnWd 9GItCvjm0iyfxllhAKHH18Fshi5WrZH5s+A40Dvjrg+VZ7s660Sy32m3Nv37veLYaMkc UaPy4WNH5bTorYApPMPkxVijYNE6Q78/k4AJ0a9ynUHYj4AJ/bHx9q/worfEceEBMKmP lOFA== X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1781031410; x=1781636210; h=content-transfer-encoding:mime-version:references:in-reply-to :message-id:date:subject:cc:to:from:x-gm-gg:x-gm-message-state:from :to:cc:subject:date:message-id:reply-to; bh=16iV7RIIpsvJlA2HjI7+KG5mxLD2wZSYZrTwJS1TsvY=; b=brsPdhisAsdqbE+QTCVzknUw6MsdnzjywFvsOjfs9hzfYw10M5xiYJ3rxJSPth/6wd 8HbmzyNfhFwBoC21V32CDNueSJo9FeDW2m2vjYnMcJJG6g2APjeJobdul7V5wZIAW8Jp lX7Mg5BNGYjQVEjXfoi1QtECOCDy6RRdQXCUJW9jNOkGcEuu+MrfIKHtFI0dvQ2eUY2K I+NTbSxZaOxs3lwIStliqCkL+hHMrRwpgsYKmCTP6yLgqS2/pJzuTD14EnEyUzLAYRJK ZVUIMZ+kW/II0ywzxR9tBOGWhLm7SjTkii0KiBxoM4Mu5HtU7QlTwLzPC5cgJ6taR+QD ySLQ== X-Forwarded-Encrypted: i=1; AFNElJ+U7SRfFmdRHh5Sm1RPkFSQW+hiMI4zfOoZHFz266gfDVB8Fr8QLtus4eRiiOi79dAnA/sF9EJODO+UVVY=@vger.kernel.org X-Gm-Message-State: AOJu0YxfSs+fDHxrBIGt7cQb6s1PC/VYElCfyH9MggKOG5h932qEwX+k Q0s88dq3kcG1B7yncM+DARksGNjC17eQaJ7pOrkLdvhGOycH3Pj6kWhOqTMnJYVnGE4= X-Gm-Gg: Acq92OFWUBmOgEjSi60/wdtJfuM8phBe0PvpcsMoVRycV0bsSkhjc3Bv8POzgIivj3i Dl1Jacb/p5qiSlBtkN+e2vBpiRog/vBw8xFPS34MnH0/5MS9nn3xW6cvL8s6NaGgtng9j6BRP2Y jQ91kn9jUfrfPgnOXy/KqTf3huXvzIpelT2z3Awl84j25pBSlv0zZdw8SZ10B3Kyq4ZAdKzZf0P 29hqaeFh3G7lyl0klZa/pv2QyNPPw3bLAwaegue3CUbbu7fHNFl+m6aUW3rR1SJoMyOwlYM54ab WwvXDUH06f1lJUIzkYjCvg2v02jTNHJxRq3WPA4Z2agbdHsAAMZ9zNYncAcvf3+taGZdlSqtqoD MZvysEpxolwIdnYuzXiqgyvZ6l1TpAtriImM2JeLNNWNgWgWFBlwF5k0nwt6KOsJ1+O1Sts+KDp aCSaR1ge/pYT5n9UH9VHGmVmAAW4D4e96Kivm6Qg== X-Received: by 2002:a0c:ff49:0:b0:8a5:104b:e37b with SMTP id 6a1803df08f44-8cee629b32amr281614486d6.42.1781031410153; Tue, 09 Jun 2026 11:56:50 -0700 (PDT) Received: from localhost ([161.35.96.86]) by smtp.gmail.com with UTF8SMTPSA id 6a1803df08f44-8cecd06d600sm212001306d6.35.2026.06.09.11.56.49 (version=TLS1_3 cipher=TLS_AES_128_GCM_SHA256 bits=128/128); Tue, 09 Jun 2026 11:56:49 -0700 (PDT) From: Samuel Moelius To: Jamal Hadi Salim Cc: Samuel Moelius , Jiri Pirko , "David S. Miller" , Eric Dumazet , Jakub Kicinski , Paolo Abeni , Simon Horman , Max Tottenham , Pedro Tammela , Josh Hunt , netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: [PATCH net v3 1/2] net/sched: act_pedit: require matching IPv4 L4 protocol Date: Tue, 9 Jun 2026 18:56:34 +0000 Message-ID: <20260609185636.1599359-2-sam.moelius@trailofbits.com> X-Mailer: git-send-email 2.43.0 In-Reply-To: <20260609185636.1599359-1-sam.moelius@trailofbits.com> References: <20260609185636.1599359-1-sam.moelius@trailofbits.com> Precedence: bulk X-Mailing-List: linux-kernel@vger.kernel.org List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit The extended IPv4 L4 header mode in act_pedit can select TCP or UDP header fields without confirming that the IPv4 protocol field matches the selected transport header. That lets a rule written for TCP or UDP modify unrelated payload bytes in a packet carrying a different protocol. Verify that the IPv4 header is long enough, that the protocol matches the selected TCP or UDP header, and that the packet is not a non-initial fragment before applying TCP or UDP extended header edits. Fixes: 6c02568fd1ae ("net/sched: act_pedit: Parse L3 Header for L4 offset") Assisted-by: Codex:gpt-5.5-cyber-preview Signed-off-by: Samuel Moelius --- Changes in v2: - Add check of iph->frag_off & htons(IP_OFFSET) net/sched/act_pedit.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/net/sched/act_pedit.c b/net/sched/act_pedit.c index bd3b1da3cd63..0d652dea4a69 100644 --- a/net/sched/act_pedit.c +++ b/net/sched/act_pedit.c @@ -18,6 +18,7 @@ #include #include #include +#include #include #include #include @@ -331,6 +332,9 @@ static int pedit_l4_skb_offset(struct sk_buff *skb, int *hoffset, const int head if (!iph) goto out; + if (iph->ihl < 5 || iph->protocol != header_type || + (iph->frag_off & htons(IP_OFFSET))) + goto out; *hoffset = noff + iph->ihl * 4; ret = 0; break; -- 2.43.0