mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
synced 2024-09-28 05:12:49 +00:00
Fix write to cloned skb in ipv6_hop_ioam()
ioam6_fill_trace_data() writes inside the skb payload without ensuring
it's writeable (e.g., not cloned). This function is called both from the
input and output path. The output path (ioam6_iptunnel) already does the
check. This commit provides a fix for the input path, inside
ipv6_hop_ioam(). It also updates ip6_parse_tlv() to refresh the network
header pointer ("nh") when returning from ipv6_hop_ioam().
Fixes: 9ee11f0fff
("ipv6: ioam: Data plane support for Pre-allocated Trace")
Reported-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Justin Iurman <justin.iurman@uliege.be>
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
This commit is contained in:
parent
7d2a894d7f
commit
f198d933c2
1 changed files with 10 additions and 0 deletions
|
@ -177,6 +177,8 @@ static bool ip6_parse_tlv(bool hopbyhop,
|
||||||
case IPV6_TLV_IOAM:
|
case IPV6_TLV_IOAM:
|
||||||
if (!ipv6_hop_ioam(skb, off))
|
if (!ipv6_hop_ioam(skb, off))
|
||||||
return false;
|
return false;
|
||||||
|
|
||||||
|
nh = skb_network_header(skb);
|
||||||
break;
|
break;
|
||||||
case IPV6_TLV_JUMBO:
|
case IPV6_TLV_JUMBO:
|
||||||
if (!ipv6_hop_jumbo(skb, off))
|
if (!ipv6_hop_jumbo(skb, off))
|
||||||
|
@ -943,6 +945,14 @@ static bool ipv6_hop_ioam(struct sk_buff *skb, int optoff)
|
||||||
if (!skb_valid_dst(skb))
|
if (!skb_valid_dst(skb))
|
||||||
ip6_route_input(skb);
|
ip6_route_input(skb);
|
||||||
|
|
||||||
|
/* About to mangle packet header */
|
||||||
|
if (skb_ensure_writable(skb, optoff + 2 + hdr->opt_len))
|
||||||
|
goto drop;
|
||||||
|
|
||||||
|
/* Trace pointer may have changed */
|
||||||
|
trace = (struct ioam6_trace_hdr *)(skb_network_header(skb)
|
||||||
|
+ optoff + sizeof(*hdr));
|
||||||
|
|
||||||
ioam6_fill_trace_data(skb, ns, trace, true);
|
ioam6_fill_trace_data(skb, ns, trace, true);
|
||||||
break;
|
break;
|
||||||
default:
|
default:
|
||||||
|
|
Loading…
Reference in a new issue