Re: [PATCH net-next v2 1/2] net: Guard for gso_segs overflow in skb_segment

Paolo Abeni <[email protected]>
Newsgroups gmane.linux.network
Message-ID <[email protected]>
On 8/13/26 7:46 PM, Alice Mikityanska wrote:
> From: Alice Mikityanska <[email protected]>
> 
> skb_segment calculates 32-bit partial_segs as len / gso_size, and then
> assigns it to the 16-bit gso_segs field. The division might overflow in
> some edge cases where the SKB is BIG TCP (65536 <= len <= 8*65535), and
> gso_size < TCP_MIN_GSO_SIZE = 8. While normally this can't happen due to
> TCP_MIN_GSO_SIZE, an AF_PACKET PACKET_VNET_HDR socket can generate such
> a malformed packet.
> 
> Blocking malformed virtio_net packets is implemented in the next patch,
> but this patch clamps partial_segs in skb_segment itself for more
> generic robustness. Should len / gso_size happen to be bigger than
> 65535 in partial GSO, skb_segment will now just produce more than two
> output SKBs, all of which will be valid with gso_segs <= 65535.

Minor nit: I think it would make sense to re-order the patches.

> Signed-off-by: Alice Mikityanska <[email protected]>
> ---
>  net/core/skbuff.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/net/core/skbuff.c b/net/core/skbuff.c
> index c82a1472a5ea..439cbfeb02bd 100644
> --- a/net/core/skbuff.c
> +++ b/net/core/skbuff.c
> @@ -4860,7 +4860,7 @@ struct sk_buff *skb_segment(struct sk_buff *head_skb,
>  		 * doesn't fit into an MSS sized block, so take care of that
>  		 * now.
>  		 */
> -		partial_segs = len / mss;
> +		partial_segs = min(len / mss, GSO_MAX_SEGS);

Since on top of patch 2/2 the min() should always be a no-op, what about
instead:

		if (WARN_ON_ONCE(len/mss > GSO_MAX_SEGS))
			return ERR_PTR(-EINVAL);

?

/P
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.