Re: [PATCH] net: tulip: xircom_cb: drop runt frames before skb copy
Pablo Vallespín Aranguren <[email protected]> Fri, 31 Jul 2026 22:56:02 +0200
| Newsgroups | org.kernel.vger.linux-parisc,org.kernel.vger.linux-kernel,org.kernel.vger.netdev |
|---|---|
| Message-ID | <am0L4gNtPJaMPx_9@ThinkPad-P15> |
On Fri, Jul 31, 2026 at 08:26:29PM +0100, David Laight wrote: > On Fri, 31 Jul 2026 20:33:34 +0200 > Pablo Vallespín Aranguren <[email protected]> wrote: > > Have you checked that that hardware can actually set a short value? > I'd expect that packets shorter than 64 bytes (including the crc) are > dropped as 'runts' and probably don't even use a ring entry. I haven't verified how the real Xircom firmware handles runt frames (I don't own this hardware). I tested with Qemu's emulated NIC, the device itself does validate and reject negative-size values before sending them to the driver. > Of course, if you think the device might lie all bets are off. > (Without an iommu is can write anywhere in host memory...) I took into account that the hardware could glitch or a misbehaving/fake card could be used. I modified the emulated NIC to mimic this behaviour, and given that the driver does not perform a check on its own (to validate that pkt_len is not negative) it does lead to a kernel panic. Best, Pablo > > Signed-off-by: Pablo Vallespín Aranguren <[email protected]> > > Assisted-by: gkh_clanker_t1000 > > --- > > drivers/net/ethernet/dec/tulip/xircom_cb.c | 5 +++++ > > 1 file changed, 5 insertions(+) > > > > diff --git a/drivers/net/ethernet/dec/tulip/xircom_cb.c b/drivers/net/ethernet/dec/tulip/xircom_cb.c > > index e5d2ede13845..62c64da1c8fa 100644 > > --- a/drivers/net/ethernet/dec/tulip/xircom_cb.c > > +++ b/drivers/net/ethernet/dec/tulip/xircom_cb.c > > @@ -1110,6 +1110,11 @@ investigate_read_descriptor(struct net_device *dev, struct xircom_private *card, > > /* minus 4, we don't want the CRC */ > > struct sk_buff *skb; > > > > + if (pkt_len < 0) { > > + dev->stats.rx_length_errors++; > > + goto out; > > + } > > + > > if (pkt_len > 1518) { > > netdev_err(dev, "Packet length %i is bogus\n", pkt_len); > > pkt_len = 1518; >