Re: [PATCH net] mpls: reload header after pskb_may_pull()
From: patchwork-bot+netdevbpf
Date: Tue Aug 18 2026 - 05:21:50 EST
Hello:
This patch was applied to netdev/net.git (main)
by Paolo Abeni <pabeni@xxxxxxxxxx>:
On Fri, 14 Aug 2026 17:54:04 +0800 you wrote:
> mpls_select_multipath() calls mpls_multipath_hash() to choose a nexthop
> when an MPLS route has multiple nexthops. While walking the MPLS label
> stack, the hash routine caches hdr for the current label. After finding
> the bottom-of-stack label, it calls pskb_may_pull() before reading the
> inner IP header.
>
> If an skb is constructed with the inner IP header in nonlinear data and
> insufficient tailroom in the linear head, pskb_may_pull() calls
> pskb_expand_head() to replace the skb head and free the old one. This
> leaves hdr pointing to freed memory. The IPv6 path can invalidate hdr
> again when it performs a second pull for the larger header.
>
> [...]
Here is the summary with links:
- [net] mpls: reload header after pskb_may_pull()
https://git.kernel.org/netdev/net/c/29e63b8d9fc1
You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html