mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-09-18 23:19:34 +02:00
net: devmem: prevent net-iov / page mixing
We should either have net_iov or page backed frags in a single skb,
otherwise it blows up down the stack. Don't allow mixing in
zerocopy_fill_skb_from_devmem().
Fixes: bd61848900 ("net: devmem: Implement TX path")
Cc: stable@vger.kernel.org
Signed-off-by: Pavel Begunkov <asml.silence@gmail.com>
Acked-by: Stanislav Fomichev <sdf@fomichev.me>
Reviewed-by: Mina Almasry <almasrymina@google.com>
Reviewed-by: Bobby Eshleman <bobbyeshleman@meta.com>
Link: https://patch.msgid.link/e3199788c4732545627a4721097ebb71ad737bab.1785150502.git.asml.silence@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
committed by
Jakub Kicinski
parent
683c6ba6e5
commit
53a43508ee
@@ -712,6 +712,9 @@ zerocopy_fill_skb_from_devmem(struct sk_buff *skb, struct iov_iter *from,
|
||||
size_t virt_addr, size, off;
|
||||
struct net_iov *niov;
|
||||
|
||||
if (i && skb_frags_readable(skb))
|
||||
return -EFAULT;
|
||||
|
||||
/* Devmem filling works by taking an IOVEC from the user where the
|
||||
* iov_addrs are interpreted as an offset in bytes into the dma-buf to
|
||||
* send from. We do not support other iter types.
|
||||
|
||||
Reference in New Issue
Block a user