Re: [PATCH net v4 2/2] pppoe: drop PFC frames

Simon Horman <[email protected]> Fri, 10 Apr 2026 18:11:15 +0100
Newsgroups org.kernel.vger.linux-ppp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev
Message-ID <[email protected]>
On Fri, Apr 10, 2026 at 11:36:21AM +0800, Qingfang Deng wrote:
> RFC 2516 Section 7 states that Protocol Field Compression (PFC) is NOT
> RECOMMENDED for PPPoE. In practice, pppd does not support negotiating
> PFC for PPPoE sessions, and the current PPPoE driver assumes an
> uncompressed (2-byte) protocol field. However, the generic PPP layer
> function ppp_input() is not aware of the negotiation result, and still
> accepts PFC frames.
> 
> If a peer with a broken implementation or an attacker sends a frame with
> a compressed (1-byte) protocol field, the subsequent PPP payload is
> shifted by one byte. This causes the network header to be 4-byte
> misaligned, which may trigger unaligned access exceptions on some
> architectures.
> 
> To reduce the attack surface, drop PPPoE PFC frames. Introduce
> ppp_skb_is_compressed_proto() helper function to be used in both
> ppp_generic.c and pppoe.c to avoid open-coding.
> 
> Fixes: 7fb1b8ca8fa1 ("ppp: Move PFC decompression to PPP generic layer")
> Signed-off-by: Qingfang Deng <[email protected]>
> ---
> Changes in v4:
>  Update Fixes tag as suggested by AI review
>  Link to v3: https://lore.kernel.org/r/[email protected]
> Changes in v3:
>  Fix kdoc warning
>  Link to v2: https://lore.kernel.org/r/[email protected]

Reviewed-by: Simon Horman <[email protected]>