[PATCH mptcp-net] mptcp: options: handle MPC data + csum reqd + no csum
"Matthieu Baerts (NGI0)" <[email protected]>
| Newsgroups | dev.linux.lists.mptcp |
|---|---|
| Message-ID | <20260805-mptcp-opt-mpc-csumreqd-no-csum-v1-1-cb2ad0b9feac@kernel.org> |
Before this modification, a remote peer could send an MP_CAPABLE with
data, with the checksum flag set, but without adding the actual 2 bytes
of checksum. As a result, uninitialised bytes could be used for the
'csum' field.
That was not a critical issue, because this 'csum' field is only used to
compare with the expected one, if previously negotiated in the 3WHS.
Worst case, the checksum is likely wrong, a fallback is done without a
reject if the negotiation was done earlier. That's OK.
Yet, better to take the expected path with this case: only look at the
checksum field if the checksum flag is present.
Fixes: 208e8f66926c ("mptcp: receive checksum for MP_CAPABLE with data")
Link: https://netdev-ai.bots.linux.dev/sashiko/#/patchset/20260803-net-mptcp-misc-fixes-7-2-rc6-v2-0-b8f496d71664%40kernel.org?part=1
Signed-off-by: Matthieu Baerts (NGI0) <[email protected]>
---
net/mptcp/options.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/mptcp/options.c b/net/mptcp/options.c
index e1b38fe5faf8..e94d4ad4dee8 100644
--- a/net/mptcp/options.c
+++ b/net/mptcp/options.c
@@ -119,9 +119,9 @@ static void mptcp_parse_option(const struct sk_buff *skb,
mp_opt->data_len = get_unaligned_be16(ptr);
ptr += 2;
}
- if (opsize == TCPOLEN_MPTCP_MPC_ACK_DATA_CSUM) {
+ if (opsize == TCPOLEN_MPTCP_MPC_ACK_DATA_CSUM &&
+ (mp_opt->suboptions & OPTION_MPTCP_CSUMREQD)) {
mp_opt->csum = get_unaligned((__force __sum16 *)ptr);
- mp_opt->suboptions |= OPTION_MPTCP_CSUMREQD;
ptr += 2;
}
pr_debug("MP_CAPABLE version=%x, flags=%x, optlen=%d sndr=%llu, rcvr=%llu len=%d csum=%u\n",
---
base-commit: 064fb643fcfcdddbad6da71da8f1ab206f018af7
change-id: 20260805-mptcp-opt-mpc-csumreqd-no-csum-3f145fa19c4d
Best regards,
--
Matthieu Baerts (NGI0) <[email protected]>