Re: [PATCH net] pppoe: reload header pointer after dev_hard_header()

From: Eric Dumazet

Date: Wed Jul 22 2026 - 08:32:37 EST


On Wed, Jul 22, 2026 at 1:17 PM Vadim Fedorenko
<vadim.fedorenko@xxxxxxxxx> wrote:
>
> On 22/07/2026 10:38, Asim Viladi Oglu Manizada wrote:
> > pppoe_sendmsg() saves a pointer to the PPPoE header before calling
> > dev_hard_header(). Device header callbacks are allowed to reallocate the
> > skb head, invalidating pointers into it.
> >
> > This can happen when a send is blocked in copy_from_user() while the first
> > non-Ethernet port is added to an empty team device. The team's delegated
> > GRE header callback then expands the skb head. PPPoE subsequently writes
> > six bytes through the stale pointer into the freed head.
> >
> > Reload the PPPoE header through the skb's network-header offset after
> > device header creation. pskb_expand_head() updates that offset when it
> > relocates the head.
> >
> > Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
> > Cc: stable@xxxxxxxxxxxxxxx
> > Assisted-by: avom-custom-harness:gpt-5.5-qwen3.6-mod-mix
> > Signed-off-by: Asim Viladi Oglu Manizada <manizada@xxxxx>
> > ---
> > drivers/net/ppp/pppoe.c | 1 +
> > 1 file changed, 1 insertion(+)
> >
> > diff --git a/drivers/net/ppp/pppoe.c b/drivers/net/ppp/pppoe.c
> > index 4a018acb5..6874a1a8e 100644
> > --- a/drivers/net/ppp/pppoe.c
> > +++ b/drivers/net/ppp/pppoe.c
> > @@ -825,6 +825,7 @@ static int pppoe_sendmsg(struct socket *sock, struct msghdr *m,
> > dev_hard_header(skb, dev, ETH_P_PPP_SES,
> > po->pppoe_pa.remote, NULL, total_len);
> >
> > + ph = pppoe_hdr(skb);
> > memcpy(ph, &hdr, sizeof(struct pppoe_hdr));
> >
> > ph->length = htons(total_len);
> Reviewed-by: Vadim Fedorenko <vadim.fedorenko@xxxxxxxxx>

Reviewed-by: Eric Dumazet <edumazet@xxxxxxxxxx>