@@ -2816,7 +2816,44 @@ struct sk_buff *skb_segment(struct sk_buff *skb, netdev_features_t features)
hsize = len;
if (!hsize && i >= nfrags) {
- BUG_ON(fskb->len != len);
+ if (fskb->len != len) {
+ if (skb_has_frag_list(fskb)) {
+ net_warn_ratelimited(
+ "skb_segment: "
+ "nested frag_list detected");
+ err = -EINVAL;
+ goto err;
+ }
+
+ nskb = skb_segment(fskb, features);
+
+ err = PTR_ERR(nskb);
+ if (IS_ERR(nskb))
+ goto err;
+ err = -ENOMEM;
+
+ if (segs)
+ tail->next = nskb;
+ else
+ segs = nskb;
+
+ tail = nskb;
+ while (tail->next)
+ tail = tail->next;
+
+ if (fskb->next && tail->len != len) {
+ net_warn_ratelimited(
+ "skb_segment: "
+ "illegal GSO fragment: %u %u",
+ tail->len, len);
+ err = -EINVAL;
+ goto err;
+ }
+
+ len = fskb->len;
+ fskb = fskb->next;
+ continue;
+ }
pos += len;
nskb = skb_clone(fskb, GFP_ATOMIC);
@@ -2905,7 +2942,14 @@ struct sk_buff *skb_segment(struct sk_buff *skb, netdev_features_t features)
if (pos < offset + len) {
struct sk_buff *fskb2 = fskb;
- BUG_ON(pos + fskb->len != offset + len);
+ if (pos + fskb->len != offset + len) {
+ net_warn_ratelimited(
+ "skb_segment: "
+ "illegal GSO trailer: %u %u",
+ pos + fskb->len, offset + len);
+ err = -EINVAL;
+ goto err;
+ }
pos += fskb->len;
fskb = fskb->next;