|
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index] Re: [PATCH net] xen/netfront: drop RX packets with a short Ethernet header
Hello:
This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@xxxxxxxxxx>:
On Wed, 07 Oct 2026 17:55:40 +0000 you wrote:
> handle_incoming_queue() pulls pull_to bytes into the head before
> calling eth_type_trans(). pull_to is the length of the first RX slot,
> capped at RX_COPY_THRESHOLD, and that length comes from the backend.
> Nothing checks it against ETH_HLEN.
>
> If the first slot is shorter than ETH_HLEN and more slots follow, the
> head ends up shorter than an Ethernet header while skb->len is longer,
> and eth_type_trans() BUG()s in __skb_pull(). If the whole packet is
> shorter than ETH_HLEN, eth_type_trans() reads the header past the end
> of the data instead.
>
> [...]
Here is the summary with links:
- [net] xen/netfront: drop RX packets with a short Ethernet header
https://git.kernel.org/netdev/net/c/089e58805c45
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
|
![]() |
Lists.xenproject.org is hosted with RackSpace, monitoring our |