Re: [PATCH net] amt: pull the AMT header behind the transport header in amt_parse_type()

From: Eric Dumazet

Date: Thu Oct 01 2026 - 03:15:52 EST


On Mon, Sep 28, 2026 at 8:16 PM Omar Ramadan <omar@xxxxxxxxxxxxx> wrote:
>
> A gateway's encap socket passes ICMP errors to amt_err_lookup(), which
> calls amt_parse_type() on the quoted datagram to see which AMT message
> failed. On that path skb->data points at the quoted IP header and the
> transport header at the quoted UDP header, and icmp_socket_deliver()
> only guarantees the quoted IP header plus 8 bytes, that is, up to the
> end of the UDP header.
>
> amt_parse_type() pulls sizeof(struct udphdr) + sizeof(struct amt_header)
> bytes from skb->data, which on this path stays inside the quoted IP
> header, and then reads the AMT header behind udp_hdr(skb). An ICMP error
> that quotes only the IP and UDP headers of a Request, the minimum RFC 792
> asks for, therefore makes it read past the pulled data, and past the end
> of the packet when nothing follows.
>
> Pull up to the transport header plus the UDP and AMT headers, as
> vxlan_err_lookup() does. amt_rcv() is called with the transport header
> at skb->data, so the pull on the receive path does not change.
>
> Fixes: cbc21dc1cfe9 ("amt: add data plane of amt interface")
> Signed-off-by: Omar Ramadan <omar@xxxxxxxxxxxxx>
> ---

Reviewed-by: Eric Dumazet <edumazet@@google.com>

Please read https://lore.kernel.org/netdev/20260928181557.85796-1-omar@xxxxxxxxxxxxx/