Re: [PATCH net v3] net: tun: bound receive headroom
| Newsgroups | gmane.linux.network |
|---|---|
| Message-ID | <178667783289.3150297.10268280469070580698.git-patchwork-notify@kernel.org> |
Hello: This patch was applied to netdev/net.git (main) by Jakub Kicinski <[email protected]>: On Wed, 12 Aug 2026 01:21:53 +0000 you wrote: > tun_get_user() uses tun->align both as skb headroom and when choosing how > much packet data to keep linear. OVS can propagate an oversized headroom > request from another port to TUN or TAP. > > When align is larger than the usable space in a one-page skb head, > SKB_MAX_HEAD(align) underflows and the result becomes negative when stored > in good_linear. That value later wraps when assigned to the size_t linear > variable, and tun_alloc_skb() can place skb->data outside the allocated > head. > > [...] Here is the summary with links: - [net,v3] net: tun: bound receive headroom https://git.kernel.org/netdev/net/c/447c9303942c You are awesome, thank you! -- Deet-doot-dot, I am a bot. https://korg.docs.kernel.org/patchwork/pwbot.html