| Message ID | 20260828085522.31015-1-arefev@swemel.ru |
|---|---|
| State | Handled Elsewhere, archived |
| Headers | show |
| Series | [5.10/6.1] ipvs: reload ip header after head reallocation | expand |
On Fri, Aug 28, 2026 at 11:55:21AM +0300, Denis Arefev wrote: > From: Florian Westphal <fw@strlen.de> > > commit a2f57827bf7c695b8c72dc4511cae8e86582369d upstream. > > __ip_vs_get_out_rt() calls skb_ensure_writable() which may > reallocate skb->head. > > Fixes: 8d8e20e2d7bb ("ipvs: Decrement ttl") > Cc: stable@vger.kernel.org > Assisted-by: Claude:claude-sonnet-4-6 > Acked-by: Julian Anastasov <ja@ssi.bg> > Signed-off-by: Florian Westphal <fw@strlen.de> > [Denis Arefev: adapted for 5.10/6.1: keep EnterFunction/LeaveFunction > instrumentation] yea, the backport seems fine and match commit a2f57827bf7c69 ("ipvs: reload ip header after head reallocation") > Signed-off-by: Denis Arefev <arefev@swemel.ru> Reviewed-by: Breno Leitao <leitao@debian.org>
> commit a2f57827bf7c695b8c72dc4511cae8e86582369d upstream. > > __ip_vs_get_out_rt() calls skb_ensure_writable() which may > reallocate skb->head. Queued for 6.1, 5.15 and 5.10, thanks. 5.15 has the same dangling iph in ip_vs_bypass_xmit(), so I applied the same patch there as well.
diff --git a/net/netfilter/ipvs/ip_vs_xmit.c b/net/netfilter/ipvs/ip_vs_xmit.c index 9e199f00eea7..29ca141e3795 100644 --- a/net/netfilter/ipvs/ip_vs_xmit.c +++ b/net/netfilter/ipvs/ip_vs_xmit.c @@ -718,15 +718,13 @@ int ip_vs_bypass_xmit(struct sk_buff *skb, struct ip_vs_conn *cp, struct ip_vs_protocol *pp, struct ip_vs_iphdr *ipvsh) { - struct iphdr *iph = ip_hdr(skb); - EnterFunction(10); - if (__ip_vs_get_out_rt(cp->ipvs, cp->af, skb, NULL, iph->daddr, - IP_VS_RT_MODE_NON_LOCAL, NULL, ipvsh) < 0) + if (__ip_vs_get_out_rt(cp->ipvs, cp->af, skb, NULL, ip_hdr(skb)->daddr, + IP_VS_RT_MODE_NON_LOCAL, NULL, ipvsh) < 0) goto tx_error; - ip_send_check(iph); + ip_send_check(ip_hdr(skb)); /* Another hack: avoid icmp_send in ip_fragment */ skb->ignore_df = 1;