aboutsummaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorJiri Benc <jbenc@redhat.com>2016-03-21 12:50:05 -0400
committerDavid S. Miller <davem@davemloft.net>2016-03-21 13:32:19 -0400
commit7d34fa75d3ee99a90ebb33c2917aa9152fb36a9c (patch)
treedfdf5f6576e837b63836a18242d231350f89af5c
parent5692d7ea4183b8dd5a49d73d6a4436aa22929b7b (diff)
vxlan: fix too large pskb_may_pull with remote checksum
vxlan_remcsum is called after iptunnel_pull_header and thus the skb has vxlan header already pulled. Don't include vxlan header again in the calculation. Signed-off-by: Jiri Benc <jbenc@redhat.com> Signed-off-by: David S. Miller <davem@davemloft.net>
-rw-r--r--drivers/net/vxlan.c6
1 files changed, 2 insertions, 4 deletions
diff --git a/drivers/net/vxlan.c b/drivers/net/vxlan.c
index 7bfcb9a62a5d..1c0fa364323e 100644
--- a/drivers/net/vxlan.c
+++ b/drivers/net/vxlan.c
@@ -1143,7 +1143,7 @@ static int vxlan_igmp_leave(struct vxlan_dev *vxlan)
1143static bool vxlan_remcsum(struct vxlanhdr *unparsed, 1143static bool vxlan_remcsum(struct vxlanhdr *unparsed,
1144 struct sk_buff *skb, u32 vxflags) 1144 struct sk_buff *skb, u32 vxflags)
1145{ 1145{
1146 size_t start, offset, plen; 1146 size_t start, offset;
1147 1147
1148 if (!(unparsed->vx_flags & VXLAN_HF_RCO) || skb->remcsum_offload) 1148 if (!(unparsed->vx_flags & VXLAN_HF_RCO) || skb->remcsum_offload)
1149 goto out; 1149 goto out;
@@ -1151,9 +1151,7 @@ static bool vxlan_remcsum(struct vxlanhdr *unparsed,
1151 start = vxlan_rco_start(unparsed->vx_vni); 1151 start = vxlan_rco_start(unparsed->vx_vni);
1152 offset = start + vxlan_rco_offset(unparsed->vx_vni); 1152 offset = start + vxlan_rco_offset(unparsed->vx_vni);
1153 1153
1154 plen = sizeof(struct vxlanhdr) + offset + sizeof(u16); 1154 if (!pskb_may_pull(skb, offset + sizeof(u16)))
1155
1156 if (!pskb_may_pull(skb, plen))
1157 return false; 1155 return false;
1158 1156
1159 skb_remcsum_process(skb, (void *)(vxlan_hdr(skb) + 1), start, offset, 1157 skb_remcsum_process(skb, (void *)(vxlan_hdr(skb) + 1), start, offset,