Skip to content

Commit 430ea57

Browse files
Chen YanJunklassert
authored andcommitted
xfrm: iptfs: propagate SKBFL_SHARED_FRAG in iptfs_skb_add_frags()
When iptfs_skb_add_frags() copies frag references from the source frag walk into a new SKB, it increments the page reference count via __skb_frag_ref() but does not propagate SKBFL_SHARED_FRAG to the destination SKB's skb_shinfo->flags. If the source SKB carries shared frags (e.g. from a page-pool backed receive path), the new inner SKB will appear to ESP as having privately owned frags. A subsequent esp_input() call for a nested transport-mode SA then takes the no-COW fast path and decrypts in place, writing over pages that are still referenced by the outer IPTFS SKB. This causes kernel-visible memory corruption and can trigger a panic. All other frag-transfer helpers in the kernel (skb_try_coalesce, skb_gro_receive, __pskb_copy_fclone, skb_shift, skb_segment) correctly propagate SKBFL_SHARED_FRAG; align iptfs_skb_add_frags() with this convention by setting the flag inside the loop immediately after __skb_frag_ref() and nr_frags++, so every exit path that attaches a frag unconditionally propagates SKBFL_SHARED_FRAG. Fixes: 5f2b6a9 ("xfrm: iptfs: add skb-fragment sharing code") Signed-off-by: Chen YanJun <moomichen@tencent.com> Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
1 parent 2538bd3 commit 430ea57

1 file changed

Lines changed: 1 addition & 0 deletions

File tree

net/xfrm/xfrm_iptfs.c

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -480,6 +480,7 @@ static int iptfs_skb_add_frags(struct sk_buff *skb,
480480
}
481481
__skb_frag_ref(tofrag);
482482
shinfo->nr_frags++;
483+
shinfo->flags |= SKBFL_SHARED_FRAG;
483484

484485
/* see if we are done */
485486
fraglen = tofrag->len;

0 commit comments

Comments
 (0)