[PATCH net 2/2] pfcp: make sure the SEID is linear before reading it

From: Haishuang Yan

Date: Wed Sep 30 2026 - 14:44:07 EST


pfcp_encap_recv() only makes sure that the UDP header and the 4 byte
PFCP header are in the linear area. When the S flag is set,
pfcp_session_recv() then reads the 8 byte SEID that follows, which is
not covered by the pskb_may_pull() check.

A short PFCP packet with the S flag set, or one whose session header
lies in a fragment, therefore makes pfcp_session_recv() read beyond the
end of the packet data, and whatever it finds there is stored in the
tunnel metadata that flower later classifies on.

Pull up to the end of the SEID before reading it, and drop packets
that are too short to contain it. Reload the header pointer afterwards
since pskb_may_pull() may reallocate the skb head.

Use offsetofend() rather than sizeof(struct pfcphdr_session): the
structure is not packed, so its size is 16 bytes because of the
alignment of the __be64 member, while the header on the wire is only 12
bytes, and valid session messages would be dropped.

Fixes: 6dd514f48110 ("pfcp: always set pfcp metadata")
Signed-off-by: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
---
drivers/net/pfcp.c | 7 +++++++
1 file changed, 7 insertions(+)

diff --git a/drivers/net/pfcp.c b/drivers/net/pfcp.c
index 1d14baf27c64..b5ebe6871cd9 100644
--- a/drivers/net/pfcp.c
+++ b/drivers/net/pfcp.c
@@ -65,6 +65,13 @@ static int pfcp_encap_recv(struct sock *sk, struct sk_buff *skb)
goto drop;

unparsed = pfcp_hdr(skb);
+ if (unparsed->flags & PFCP_SEID_FLAG) {
+ if (unlikely(!pskb_may_pull(skb, PFCP_HLEN +
+ offsetofend(struct pfcphdr_session,
+ seid))))
+ goto drop;
+ unparsed = pfcp_hdr(skb);
+ }

ip_tunnel_flags_zero(flags);
tun_dst = udp_tun_rx_dst(skb, sk->sk_family, flags, 0,
--
2.43.0