Re: [PATCH net] amt: pull the AMT header behind the transport header in amt_parse_type()

From: Eric Dumazet

Date: Thu Oct 01 2026 - 03:16:45 EST


On Thu, Oct 1, 2026 at 9:15 AM Eric Dumazet <edumazet@xxxxxxxxxx> wrote:
>
> On Mon, Sep 28, 2026 at 8:16 PM Omar Ramadan <omar@xxxxxxxxxxxxx> wrote:
> >
> > A gateway's encap socket passes ICMP errors to amt_err_lookup(), which
> > calls amt_parse_type() on the quoted datagram to see which AMT message
> > failed. On that path skb->data points at the quoted IP header and the
> > transport header at the quoted UDP header, and icmp_socket_deliver()
> > only guarantees the quoted IP header plus 8 bytes, that is, up to the
> > end of the UDP header.
> >
> > amt_parse_type() pulls sizeof(struct udphdr) + sizeof(struct amt_header)
> > bytes from skb->data, which on this path stays inside the quoted IP
> > header, and then reads the AMT header behind udp_hdr(skb). An ICMP error
> > that quotes only the IP and UDP headers of a Request, the minimum RFC 792
> > asks for, therefore makes it read past the pulled data, and past the end
> > of the packet when nothing follows.
> >
> > Pull up to the transport header plus the UDP and AMT headers, as
> > vxlan_err_lookup() does. amt_rcv() is called with the transport header
> > at skb->data, so the pull on the receive path does not change.
> >
> > Fixes: cbc21dc1cfe9 ("amt: add data plane of amt interface")
> > Signed-off-by: Omar Ramadan <omar@xxxxxxxxxxxxx>
> > ---
>
> Reviewed-by: Eric Dumazet <edumazet@@google.com>

This was meant to be:

Reviewed-by: Eric Dumazet <edumazet@xxxxxxxxxx>

>
> Please read https://lore.kernel.org/netdev/20260928181557.85796-1-omar@xxxxxxxxxxxxx/