Re: [PATCH net v6 1/1] net: gso: limit recursive IP-in-IP segmentation
From: Willem de Bruijn
Date: Fri Sep 25 2026 - 17:13:54 EST
Zihan Xi wrote:
> IP-in-IP GSO can re-enter inet_gso_segment() or ipv6_gso_segment()
> for each nested IP header. encap_level tracks header bytes, not callback
> depth, so a deep chain can exhaust the kernel stack. Making
> inet_gso_segment() stackable introduced unbounded IPv4 nesting; IPIP
> GSO/TSO later made the path reachable. The IPv6 stackable path was
> introduced separately and uses the same guard.
>
> Count IPv4 and IPv6 GSO handler entries in skb_gso_cb, initialized once
> per top-level GSO operation and preserved across GRE/UDP context changes.
> Use the existing IP_TUNNEL_RECURSION_LIMIT for both handlers. The first
> five entries pass, and the sixth returns -EINVAL before dispatching
> another GSO callback.
>
> Fixes: 3347c9602955 ("ipv4: gso: make inet_gso_segment() stackable")
> Cc: stable@xxxxxxxxxxxxxxx
> Reported-by: Vega <vega@xxxxxxxxxx>
> Closes: https://lore.kernel.org/all/cover.1790157745.git.zihanx@xxxxxxxxxx/
> Assisted-by: LLM
> Co-developed-by: Luxing Yin <root@xxxxxxxxxx>
> Signed-off-by: Luxing Yin <root@xxxxxxxxxx>
> Signed-off-by: Zihan Xi <zihanx@xxxxxxxxxx>
Reviewed-by: Willem de Bruijn <willemb@xxxxxxxxxx>