Yue Haibing
691a09eeca
ip6mr: Fix skb_under_panic in ip6mr_cache_report()
[ Upstream commit 30e0191b16 ]
skbuff: skb_under_panic: text:ffffffff88771f69 len:56 put:-4
head:ffff88805f86a800 data:ffff887f5f86a850 tail:0x88 end:0x2c0 dev:pim6reg
------------[ cut here ]------------
kernel BUG at net/core/skbuff.c:192!
invalid opcode: 0000 [#1] PREEMPT SMP KASAN
CPU: 2 PID: 22968 Comm: kworker/2:11 Not tainted 6.5.0-rc3-00044-g0a8db05b571a #236
Hardware name: QEMU Standard PC (i440FX + PIIX, 1996), BIOS 1.15.0-1 04/01/2014
Workqueue: ipv6_addrconf addrconf_dad_work
RIP: 0010:skb_panic+0x152/0x1d0
Call Trace:
<TASK>
skb_push+0xc4/0xe0
ip6mr_cache_report+0xd69/0x19b0
reg_vif_xmit+0x406/0x690
dev_hard_start_xmit+0x17e/0x6e0
__dev_queue_xmit+0x2d6a/0x3d20
vlan_dev_hard_start_xmit+0x3ab/0x5c0
dev_hard_start_xmit+0x17e/0x6e0
__dev_queue_xmit+0x2d6a/0x3d20
neigh_connected_output+0x3ed/0x570
ip6_finish_output2+0x5b5/0x1950
ip6_finish_output+0x693/0x11c0
ip6_output+0x24b/0x880
NF_HOOK.constprop.0+0xfd/0x530
ndisc_send_skb+0x9db/0x1400
ndisc_send_rs+0x12a/0x6c0
addrconf_dad_completed+0x3c9/0xea0
addrconf_dad_work+0x849/0x1420
process_one_work+0xa22/0x16e0
worker_thread+0x679/0x10c0
ret_from_fork+0x28/0x60
ret_from_fork_asm+0x11/0x20
When setup a vlan device on dev pim6reg, DAD ns packet may sent on reg_vif_xmit().
reg_vif_xmit()
ip6mr_cache_report()
skb_push(skb, -skb_network_offset(pkt));//skb_network_offset(pkt) is 4
And skb_push declared as:
void *skb_push(struct sk_buff *skb, unsigned int len);
skb->data -= len;
//0xffff88805f86a84c - 0xfffffffc = 0xffff887f5f86a850
skb->data is set to 0xffff887f5f86a850, which is invalid mem addr, lead to skb_push() fails.
Fixes: 14fb64e1f4 ("[IPV6] MROUTE: Support PIM-SM (SSM).")
Signed-off-by: Yue Haibing <yuehaibing@huawei.com>
Reviewed-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Sasha Levin <sashal@kernel.org>
2023-08-11 12:08:17 +02:00
..
2023-03-17 08:50:23 +01:00
2023-03-17 08:50:25 +01:00
2022-06-09 21:52:55 -07:00
2023-08-03 10:23:59 +02:00
2022-11-07 12:26:15 +00:00
2023-04-26 14:28:43 +02:00
2022-09-29 07:17:59 +02:00
2020-07-30 16:30:55 -07:00
2021-03-04 15:26:57 -08:00
2023-02-22 12:59:54 +01:00
2023-06-28 11:12:29 +02:00
2022-10-03 07:52:13 +01:00
2023-05-30 14:03:21 +01:00
2019-05-30 11:26:32 -07:00
2023-06-14 11:15:20 +02:00
2019-10-04 11:10:56 -07:00
2022-02-08 20:41:34 -08:00
2020-06-20 21:33:57 -07:00
2023-07-23 13:49:23 +02:00
2020-11-23 18:36:21 -05:00
2022-09-20 10:21:49 -07:00
2022-02-04 20:24:45 -08:00
2022-08-29 12:47:15 +01:00
2018-10-24 14:18:16 -07:00
2022-01-20 20:18:37 -08:00
2022-10-11 17:42:58 -06:00
2023-07-27 08:50:45 +02:00
2021-02-23 11:29:52 -08:00
2023-05-11 23:03:18 +09:00
2022-09-30 12:31:46 +01:00
2019-05-30 11:26:32 -07:00
2023-04-13 16:55:22 +02:00
2023-03-22 13:33:46 +01:00
2020-06-01 14:57:14 -07:00
2022-09-30 13:10:44 +01:00
2023-08-11 12:08:17 +02:00
2022-09-29 07:18:00 +02:00
2022-10-12 17:50:37 -07:00
2022-07-15 16:43:59 +08:00
2021-09-28 13:13:40 +01:00
2021-04-27 14:02:06 -07:00
2022-10-11 17:42:55 -06:00
2022-09-29 07:18:01 +02:00
2022-08-15 11:40:28 +01:00
2022-05-16 13:03:29 +02:00
2022-10-11 17:42:58 -06:00
2023-08-11 12:08:14 +02:00
2020-11-09 15:34:44 -08:00
2019-05-30 11:26:32 -07:00
2023-08-11 12:08:15 +02:00
2022-03-03 14:38:48 +00:00
2023-08-11 12:08:14 +02:00
2020-12-08 16:22:54 -08:00
2023-04-26 14:28:34 +02:00
2022-06-28 21:23:30 -07:00
2022-07-29 12:14:03 +01:00
2022-09-20 12:33:22 +02:00
2022-09-08 18:38:30 +02:00
2023-05-17 11:53:33 +02:00
2022-07-18 12:21:54 +01:00
2022-05-03 10:15:06 +02:00
2023-08-11 12:08:15 +02:00
2021-11-16 13:16:54 +00:00
2020-07-09 12:52:37 +02:00
2022-10-12 17:50:37 -07:00
2021-11-24 17:21:42 -08:00
2023-08-11 12:08:14 +02:00
2023-05-30 14:03:20 +01:00
2023-06-28 11:12:28 +02:00
2022-03-01 12:08:40 +01:00
2022-11-22 07:16:34 +01:00
2020-04-28 11:28:36 +02:00
2020-05-06 09:40:08 +02:00
2022-09-29 07:18:00 +02:00