Re: [PATCH net] ipv4: validate checksum_start before completing checksum

From: Willem de Bruijn

Date: Wed Oct 07 2026 - 19:36:59 EST


On Wed, Oct 7, 2026 at 6:42 PM Michael S. Tsirkin <mst@xxxxxxxxxx> wrote:
>
> If a packet with bad checksum metadata gets into the ipv4 stack,
> skb_checksum_help can corrupt the network header and cause a bunch of
> mischief.
>
> This was discovered and reported by Paulos, and has been reporoduced

(minor) typo: reproduced

> by others independently since.
>
> We really shouldn't allow such packets in, but as a defence
> in depth measure, let's also check before we complete the checksum.
>
> A more complete validation at input is forthcoming, but needs more work.
>
> Assisted-by: LLM
> Fixes: f43798c27684 ("tun: Allow GSO using virtio_net_hdr")
> Fixes: bfd5f4a3d605 ("packet: Add GSO/csum offload support.")
> Reported-by: Paulos Yibelo <habte.yibelo@xxxxxxxxx>
> Closes: https://lore.kernel.org/netdev/20260922030310.8684-2-habte.yibelo@xxxxxxxxx/
> Signed-off-by: Michael S. Tsirkin <mst@xxxxxxxxxx>

Cc: stable@xxxxxxxxxxxxxxx

Reviewed-by: Willem de Bruijn <willemb@xxxxxxxxxx>

One point about sending as a single patch touching five separate
modules: nf_br_ip_fragment was only introduced in Linux 5.3.
Such a block is probably easily dropped from a stable backport.
A single patch is likely still preferable over splitting into two
(core + optional) or even five (one per module) patches.

> ---
>
> Lightly tested.

Tested by me as well and found to block the known bad input.

Touching five modules is not ideal, but could not find any other
approach that would be preferable: low risk of unintended
consequences, out of the hot path, and relatively concise.