|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] [PATCH net-next 3/9] net: niu: check for failure when pulling in the RX header
niu_process_rx_pkt() uses __pskb_pull_tail() to pull the hardware RX
header and the Ethernet header into the skb head, and ignores the
return value. If that pull failed, the skb_pull() of the RX header
right after it would BUG() in __skb_pull().
It doesn't fail today because the skb is freshly allocated, isn't
shared and has room in the head. Use pskb_may_pull() anyway and drop
the packet if it fails, rather than depending on that.
Assisted-by: LLM
Signed-off-by: Josef Bacik <josef@xxxxxxxxxxxxxx>
---
drivers/net/ethernet/sun/niu.c | 6 +++++-
1 file changed, 5 insertions(+), 1 deletion(-)
diff --git a/drivers/net/ethernet/sun/niu.c b/drivers/net/ethernet/sun/niu.c
index c74a97fe5464..d1c0e868004d 100644
--- a/drivers/net/ethernet/sun/niu.c
+++ b/drivers/net/ethernet/sun/niu.c
@@ -3488,7 +3488,11 @@ static int niu_process_rx_pkt(struct napi_struct *napi,
struct niu *np,
len += sizeof(*rh);
len = min_t(int, len, sizeof(*rh) + VLAN_ETH_HLEN);
- __pskb_pull_tail(skb, len);
+ if (unlikely(!pskb_may_pull(skb, len))) {
+ rp->rx_dropped++;
+ kfree_skb(skb);
+ return num_rcr;
+ }
rh = (struct rx_pkt_hdr1 *) skb->data;
if (np->dev->features & NETIF_F_RXHASH)
--
2.55.0
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |