android_kernel_motorola_sm6375/net
Repository files (latest commit first)
Filename Latest commit message Latest commit date
Hyunwoo Kim 06dad31134
net: skbuff: propagate shared-frag marker through frag-transfer helpers
Two frag-transfer helpers (__pskb_copy_fclone() and skb_shift()) fail
to propagate the SKBFL_SHARED_FRAG bit in skb_shinfo()->flags when
moving frags from source to destination.  __pskb_copy_fclone() defers
the rest of the shinfo metadata to skb_copy_header() after copying
frag descriptors, but that helper only carries over gso_{size,segs,
type} and never touches skb_shinfo()->flags; skb_shift() moves frag
descriptors directly and leaves flags untouched.  As a result, the
destination skb keeps a reference to the same externally-owned or
page-cache-backed pages while reporting skb_has_shared_frag() as
false.

The mismatch is harmful in any in-place writer that uses
skb_has_shared_frag() to decide whether shared pages must be detoured
through skb_cow_data().  ESP input is one such writer (esp4.c,
esp6.c), and a single nft 'dup to <local>' rule -- or any other
nf_dup_ipv4() / xt_TEE caller -- is enough to land a pskb_copy()'d
skb in esp_input() with the marker stripped, letting an unprivileged
user write into the page cache of a root-owned read-only file via
authencesn-ESN stray writes.

Set SKBFL_SHARED_FRAG on the destination whenever frag descriptors
were actually moved from the source.  skb_copy() and skb_copy_expand()
share skb_copy_header() too but linearize all paged data into freshly
allocated head storage and emerge with nr_frags == 0, so
skb_has_shared_frag() returns false on its own; they need no change.

The same omission exists in skb_gro_receive() and skb_gro_receive_list().
The former moves the incoming skb's frag descriptors into the
accumulator's last sub-skb via two paths (a direct frag-move loop and
the head_frag + memcpy path); the latter chains the incoming skb whole
onto p's frag_list.  Downstream skb_segment() reads only
skb_shinfo(p)->flags, and skb_segment_list() reuses each sub-skb's
shinfo as the nskb -- both p and lp must carry the marker.

The same omission also exists in tcp_clone_payload(), which builds an
MTU probe skb by moving frag descriptors from skbs on sk_write_queue
into a freshly allocated nskb.  The helper falls into the same family
and warrants the same fix for consistency; no TCP TX-side in-place
writer is currently known to reach a user page through this gap, but
a future consumer depending on the marker would regress silently.

The same omission exists in skb_segment(): the per-iteration flag
merge takes only head_skb's flag, and the inner switch that rebinds
frag_skb to list_skb on head_skb-frags exhaustion does not fold the
new frag_skb's flag into nskb.  Fold frag_skb's flag at both sites
so segments drawing frags from frag_list members carry the marker.

Fixes: cef401de7b ("net: fix possible wrong checksum generation")
Fixes: f4c50a4034e6 ("xfrm: esp: avoid in-place decrypt on shared skb frags")
Suggested-by: Sabrina Dubroca <sd@queasysnail.net>
Suggested-by: Sultan Alsawaf <sultan@kerneltoast.com>
Suggested-by: Ben Hutchings <ben@decadent.org.uk>
Suggested-by: Lin Ma <malin89@huawei.com>
Suggested-by: Jingguo Tan <tanjingguo@huawei.com>
Suggested-by: Aaron Esau <aaron1esau@gmail.com>
Cc: stable@vger.kernel.org
Signed-off-by: Hyunwoo Kim <imv4bel@gmail.com>
Tested-by: Rajat Gupta <rajat.gupta@oss.qualcomm.com>
Link: https://patch.msgid.link/ageeJfJHwgzmKXbh@v4bel
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
(cherry picked from commit 48f6a5356a33dd78e7144ae1faef95ffc990aae0)

Orabug: 39368828
CVE: CVE-2026-46300

Conflicts:
-	net/core/gro.c - Not present in UEK6U3
-	net/core/skbuff.c UEK6U3 doesn't have commit: 06b4feb3
	("net: group skb_shinfo zerocopy related bits together.") so
	used skb_shinfo(nskb)->tx_flags
-	net/ipv4/tcp_output.c - net/ipv4/tcp_output.c - UEK6U3 doesn't
	have commit: 73601329 ("tcp: let tcp_mtu_probe() build
	headless packets") so we need not take the hunk corresponding
	to tcp_clone_payload()

Change-Id: I19fe41c96158d2614b04d4593083826135418615
Signed-off-by: Harshit Mogalapalli <harshit.m.mogalapalli@oracle.com>
Reviewed-by: Joseph Salisbury <joseph.salisbury@oracle.com>
Signed-off-by: Alok Tiwari <alok.a.tiwari@oracle.com>
Signed-off-by: Tashfin Shakeer Rhythm <tashfinshakeerrhythm@gmail.com>
2026-07-29 03:31:11 +06:00
..
6lowpan
9p net/9p: fix double req put in p9_fd_cancelled 2025-10-29 13:59:54 +01:00
802
8021q net: vlan: sync VLAN features with lower device 2025-12-03 12:45:15 +01:00
appletalk net: appletalk: Fix use-after-free in AARP proxy probe 2025-08-28 16:21:17 +02:00
atm net: atm: fix memory leak in atm_register_sysfs when device_register fail 2025-09-09 18:43:58 +02:00
ax25 BACKPORT: net: Make sock protocol value checks more specific 2025-12-23 13:35:52 -08:00
batman-adv batman-adv: fix OOB read/write in network-coding decode 2025-09-09 18:43:59 +02:00
bluetooth This is the 5.4.302 stable release 2025-12-11 09:41:30 +00:00
bpf UPSTREAM: bpf: Move skb->len == 0 checks into __bpf_redirect 2026-01-14 18:13:04 -08:00
bpfilter UPSTREAM: net/bpfilter: Initialize pos in __bpfilter_process_sockopt 2026-02-01 20:44:55 -08:00
bridge Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4 into android13-5.4-lahaina 2026-04-30 20:46:30 +03:00
caif This is the 5.4.297 stable release 2025-09-02 10:52:40 +00:00
can This is the 5.4.300 stable release 2025-10-02 13:53:47 +00:00
ceph
core net: skbuff: propagate shared-frag marker through frag-transfer helpers 2026-07-29 03:31:11 +06:00
dcb
dccp
decnet
dns_resolver
dsa net: dsa: microchip: linearize skb for tail-tagging switches 2025-09-09 18:44:00 +02:00
embms_kernel
ethernet
hsr
ieee802154
ife
ipv4 tcp: fix an incorrect __user annotation on tcp_use_userconfig_sysctl_handler 2026-07-29 03:30:09 +06:00
ipv6 BACKPORT: net: release reference to inet6_dev pointer 2026-05-07 10:16:30 -04:00
iucv
kcm
key
l2tp
l3mdev
lapb
llc llc: fix data loss when reading from a socket in llc_ui_recvmsg() 2025-06-04 14:32:35 +02:00
mac80211 Merge android11-5.4.302(91d385eb) into msm-5.4 2026-01-30 11:41:11 +05:30
mac802154
mpls BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
ncsi net: ncsi: Fix buffer overflow in fetching version id 2025-08-28 16:21:27 +02:00
netfilter Merge tag 'LA.UM.9.14.1.r1-21100-QCM6490.QISI15.0' of https://git.codelinaro.org/clo/la/kernel/msm-5.4 into android13-5.4-lahaina 2026-04-30 20:46:30 +03:00
netlabel calipso: unlock rcu before returning -EAFNOSUPPORT 2025-06-27 11:02:50 +01:00
netlink UPSTREAM: bpf: Refactor bpf_iter_reg to have separate seq_info member 2026-01-14 18:12:07 -08:00
netrom
neuron
nfc BACKPORT: net: Fix Kconfig indentation, continued 2026-02-01 20:39:45 -08:00
nsh
openvswitch net: openvswitch: remove never-working support for setting nsh fields 2025-12-03 12:45:20 +01:00
packet BACKPORT: net: switch copy_bpf_fprog_from_user to sockptr_t 2026-01-14 18:12:35 -08:00
phonet BACKPORT: sysctl: pass kernel pointers to ->proc_handler 2025-12-23 13:36:15 -08:00
psample
qrtr
rds BACKPORT: tcp: add tcp_sock_set_keepidle 2026-01-14 17:50:47 -08:00
rfkill BACKPORT: compat_ioctl: move more drivers to compat_ptr_ioctl 2026-05-08 21:46:20 +02:00
rose rose: fix dangling neighbour pointers in rose_rt_device_down() 2025-07-17 18:25:00 +02:00
rxrpc rxrpc: Fix oops due to non-existence of prealloc backlog struct 2025-07-17 18:25:02 +02:00
sched Merge android11-5.4.302(91d385eb) into msm-5.4 2026-01-30 11:41:11 +05:30
sctp Revert "net, sctp, filter: remap copy_from_user failure error" 2026-02-01 20:44:59 -08:00
smc
strparser strparser: Fix signed/unsigned mismatch bug 2025-12-03 12:45:19 +01:00
sunrpc BACKPORT: tcp: add tcp_sock_set_keepidle 2026-01-14 17:50:47 -08:00
switchdev
tipc This is the 5.4.302 stable release 2025-12-11 09:41:30 +00:00
tls UPSTREAM: net, sk_msg: Annotate lockless access to sk_prot on clone 2025-12-23 13:36:03 -08:00
unix
vmw_vsock This is the 5.4.302 stable release 2025-12-11 09:41:30 +00:00
wimax
wireless Revert "wifi: cfg80211: Increase akm_suites array size in" 2026-05-05 20:02:19 +03:00
x25
xdp UPSTREAM: bpf: Allow for map-in-map with dynamic inner array map entries 2026-01-14 18:12:44 -08:00
xfrm BACKPORT: net: Fix Kconfig indentation, continued 2026-02-01 20:39:45 -08:00
compat.c BACKPORT: net: simplify cBPF setsockopt compat handling 2026-01-14 18:12:33 -08:00
Kconfig BACKPORT: bpf: Clean up sockmap related Kconfigs 2026-02-01 20:44:37 -08:00
Makefile
OWNERS
socket.c
sysctl_net.c
TEST_MAPPING