xdp: fix zero-copy frame layout
28Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.8epss 0.5%
exploitation probability
0.5%top 57% of all CVEs
observed exploitation
nono source reports it
In the Linux kernel, the following vulnerability has been resolved:
xdp: fix zero-copy frame layout
xdp_convert_zc_to_xdp_frame() clones an XSK packet into an order-0 page
and advertises PAGE_SIZE as its frame size. It allows the copied frame
to occupy the page tail needed by skb_shared_info and records zero
headroom even when metadata separates the frame header from packet data.
An AF_XDP zero-copy packet redirected through cpumap can therefore make
the skb overlap skb_shared_info or place it beyond the allocated page.
Limit the copied layout to SKB_WITH_OVERHEAD(PAGE_SIZE) and include the
metadata length in frame headroom. Redirect callers already handle a
NULL conversion result.
BUG: KASAN: slab-out-of-bounds in skb_gro_receive
Write of size 4 at addr ffff88800cf37004 by task cpumap/1/map:1/146
Call Trace:
skb_gro_receive (net/core/gro.c:174)
udp_gro_receive (net/ipv4/udp_offload.c:812)
inet_gro_receive (net/ipv4/af_inet.c:1539)
dev_gro_receive (net/core/gro.c:515)
gro_receive_skb (net/core/gro.c:633)
cpu_map_kthread_run (kernel/bpf/cpumap.c:395)
kthread (kernel/kthread.c:436)
ret_from_fork (arch/x86/kernel/process.c:164)
ret_from_fork_asm (arch/x86/entry/entry_64.S:255)
Kernel panic - not syncing: KASAN: panic_on_warn set ...
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Linux · LinuxReferences
https://git.kernel.org/stable/c/15d1f3c0dbe7a740f779337deb39f23cd8d002c8https://git.kernel.org/stable/c/22092730129077c302d8c947bbe0876f0280c528https://git.kernel.org/stable/c/444216dacdbebd3e52d5e704facafbb230da09e9https://git.kernel.org/stable/c/68d7cc5512238693670fc19c7a615df631e10edfhttps://git.kernel.org/stable/c/6de17275b3ccdf9887568b07e54da2e3597217cfhttps://git.kernel.org/stable/c/71283aaa6c65b3cec84caf1dc78560985737641fhttps://git.kernel.org/stable/c/ced3e18cd9b9caf630aaa1e1eac305f5192ba896https://git.kernel.org/stable/c/dcb6db9ca6515fcd3e00c93ec5e27dc7a0a7012f