Re: [PATCH net] seg6: ensure packet data is writable before modifying SRH and IPv6 DA
From: patchwork-bot+netdevbpf
Date: Mon Sep 28 2026 - 22:30:34 EST
Hello:
This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@xxxxxxxxxx>:
On Fri, 25 Sep 2026 15:38:07 +0200 you wrote:
> advance_nextseg() modifies the SRH Segments Left field and the IPv6
> destination address without ensuring the packet data is writable.
> seg6_next_csid_advance_arg() has the same problem when it advances the
> NEXT-C-SID argument in the destination address.
>
> The skb may be cloned, for example by an AF_PACKET socket receiving on
> the ingress device. advance_nextseg() and seg6_next_csid_advance_arg()
> then write into the packet data shared with the clone. A read from that
> socket can return the modified packet instead of the received one. The
> simplified path below shows this for advance_nextseg():
>
> [...]
Here is the summary with links:
- [net] seg6: ensure packet data is writable before modifying SRH and IPv6 DA
https://git.kernel.org/netdev/net/c/8ae3f4067ba4
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html