[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH net] xen/netfront: drop RX packets with a short Ethernet header



Hello:

This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@xxxxxxxxxx>:

On Wed, 07 Oct 2026 17:55:40 +0000 you wrote:
> handle_incoming_queue() pulls pull_to bytes into the head before
> calling eth_type_trans().  pull_to is the length of the first RX slot,
> capped at RX_COPY_THRESHOLD, and that length comes from the backend.
> Nothing checks it against ETH_HLEN.
> 
> If the first slot is shorter than ETH_HLEN and more slots follow, the
> head ends up shorter than an Ethernet header while skb->len is longer,
> and eth_type_trans() BUG()s in __skb_pull().  If the whole packet is
> shorter than ETH_HLEN, eth_type_trans() reads the header past the end
> of the data instead.
> 
> [...]

Here is the summary with links:
  - [net] xen/netfront: drop RX packets with a short Ethernet header
    https://git.kernel.org/netdev/net/c/089e58805c45

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html





 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.