Re: [PATCH net-next 3/9] net: skbuff: don't BUG() on a bad frag_list layout in skb_segment()
From: Mina Almasry
Date: Fri Oct 09 2026 - 12:21:47 EST
On Tue, Oct 6, 2026 at 10:10 AM Josef Bacik <josef@xxxxxxxxxxxxxx> wrote:
>
> skb_segment()'s frag_list walk assumes the GRO-shaped layout it expects
> and BUG()s when the layout doesn't match. Anybody who can get a
> malformed GSO skb to a segmentation point gets to crash the box. Most
> recently commit d5dc1e69fd72 ("inet: frags: strip GSO state from
> fragments before reassembly") fixed one that an unprivileged user could
> trigger with two writes to a tap device in their own user namespace.
> commit 3382a1ed7f77 ("net: fix udp gso skb_segment after pull from
> frag_list") fixed another.
>
> skb_segment() already has an error path for a bad layout: the
> too-many-frags check sets -EINVAL and frees the partial segment list.
> Warn once and take that path for the four layout checks. The packet
> gets dropped, which is what should happen to a packet we can't segment.
>
> The one check that runs after skb_clone() and before the clone is
> linked into the segment list frees the clone itself.
>
> Assisted-by: LLM
> Signed-off-by: Josef Bacik <josef@xxxxxxxxxxxxxx>
Reviewed-by: Mina Almasry <almasrymina@xxxxxxxxxx>