Re: [PATCH nf] ipvs: reload ip header after head reallocation
Julian Anastasov <[email protected]>
| Newsgroups | gmane.comp.security.firewalls.netfilter.devel |
|---|---|
| Message-ID | <[email protected]> |
Hello,
On Wed, 8 Jul 2026, Florian Westphal wrote:
> __ip_vs_get_out_rt() might realloc skb->head due to ttl decrement.
>
> Fixes: 8d8e20e2d7bb ("ipvs: Decrement ttl")
> Assisted-by: Claude:claude-sonnet-4-6
> Signed-off-by: Florian Westphal <[email protected]>
Looks good to me, thanks!
Acked-by: Julian Anastasov <[email protected]>
> ---
> LLM assisted find, no real-world bug report behind this.
>
> net/netfilter/ipvs/ip_vs_xmit.c | 6 ++----
> 1 file changed, 2 insertions(+), 4 deletions(-)
>
> diff --git a/net/netfilter/ipvs/ip_vs_xmit.c b/net/netfilter/ipvs/ip_vs_xmit.c
> index ce542ed4b013..9fef4335da13 100644
> --- a/net/netfilter/ipvs/ip_vs_xmit.c
> +++ b/net/netfilter/ipvs/ip_vs_xmit.c
> @@ -736,13 +736,11 @@ int
> ip_vs_bypass_xmit(struct sk_buff *skb, struct ip_vs_conn *cp,
> struct ip_vs_protocol *pp, struct ip_vs_iphdr *ipvsh)
> {
> - struct iphdr *iph = ip_hdr(skb);
> -
> - if (__ip_vs_get_out_rt(cp->ipvs, cp->af, skb, NULL, iph->daddr,
> + if (__ip_vs_get_out_rt(cp->ipvs, cp->af, skb, NULL, ip_hdr(skb)->daddr,
> IP_VS_RT_MODE_NON_LOCAL, NULL, ipvsh) < 0)
> goto tx_error;
>
> - ip_send_check(iph);
> + ip_send_check(ip_hdr(skb));
>
> /* Another hack: avoid icmp_send in ip_fragment */
> skb->ignore_df = 1;
> --
> 2.54.0
Regards
--
Julian Anastasov <[email protected]>