From d2bdf73897ec6066838ecaa73438a971345678c9 Mon Sep 17 00:00:00 2001 From: Kaustubh Pandey Date: Tue, 29 Jun 2021 10:20:54 +0530 Subject: [PATCH] net: tcp: check for NULL send head during MTU probe skb_peek() can return NULL when the socket write queue is empty. This causes problems when using tcp_for_write_queue_from_safe(), as this macro resolves down to "for (tmp = skb->next; ...", causing a NULL dereference. Fix this by indicating that the tcp send queue head can not be coalesced as there is nothing in it. This fixes the following: Unable to handle kernel NULL pointer dereference pc : tcp_write_xmit+0xe1c/0x1210 lr : tcp_write_xmit+0x38/0x1210 Call trace: tcp_write_xmit+0xe1c/0x1210 tcp_tsq_write+0x110/0x140 tcp_tasklet_func+0x120/0x170 tasklet_action_common+0xec/0x128 tasklet_action+0x20/0x28 By ending the MTU probe because of the empty send head. Change-Id: I0c3283c37ee69a4941c8d9e88519e586c7905d25 Signed-off-by: Sean Tranchetti Signed-off-by: Kaustubh Pandey --- net/ipv4/tcp_output.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/net/ipv4/tcp_output.c b/net/ipv4/tcp_output.c index 5e311e6a31d5..713c8c62c638 100644 --- a/net/ipv4/tcp_output.c +++ b/net/ipv4/tcp_output.c @@ -2071,6 +2071,9 @@ static bool tcp_can_coalesce_send_queue_head(struct sock *sk, int len) struct sk_buff *skb, *next; skb = tcp_send_head(sk); + if (!skb) + return false; + tcp_for_write_queue_from_safe(skb, next, sk) { if (len <= skb->len) break;