Skip to content

Commit a76b217

Browse files
edumazetpopcornmix
authored andcommitted
net_sched: sch_sfq: reject invalid perturb period
commit 7ca5254 upstream. Gerrard Tai reported that SFQ perturb_period has no range check yet, and this can be used to trigger a race condition fixed in a separate patch. We want to make sure ctl->perturb_period * HZ will not overflow and is positive. Tested: tc qd add dev lo root sfq perturb -10 # negative value : error Error: sch_sfq: invalid perturb period. tc qd add dev lo root sfq perturb 1000000000 # too big : error Error: sch_sfq: invalid perturb period. tc qd add dev lo root sfq perturb 2000000 # acceptable value tc -s -d qd sh dev lo qdisc sfq 8005: root refcnt 2 limit 127p quantum 64Kb depth 127 flows 128 divisor 1024 perturb 2000000sec Sent 0 bytes 0 pkt (dropped 0, overlimits 0 requeues 0) backlog 0b 0p requeues 0 Fixes: 1da177e ("Linux-2.6.12-rc2") Reported-by: Gerrard Tai <gerrard.tai@starlabs.sg> Signed-off-by: Eric Dumazet <edumazet@google.com> Cc: stable@vger.kernel.org Link: https://patch.msgid.link/20250611083501.1810459-1-edumazet@google.com Signed-off-by: Jakub Kicinski <kuba@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent 6d69235 commit a76b217

File tree

1 file changed

+8
-2
lines changed

1 file changed

+8
-2
lines changed

net/sched/sch_sfq.c

Lines changed: 8 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -656,6 +656,14 @@ static int sfq_change(struct Qdisc *sch, struct nlattr *opt,
656656
NL_SET_ERR_MSG_MOD(extack, "invalid quantum");
657657
return -EINVAL;
658658
}
659+
660+
if (ctl->perturb_period < 0 ||
661+
ctl->perturb_period > INT_MAX / HZ) {
662+
NL_SET_ERR_MSG_MOD(extack, "invalid perturb period");
663+
return -EINVAL;
664+
}
665+
perturb_period = ctl->perturb_period * HZ;
666+
659667
if (ctl_v1 && !red_check_params(ctl_v1->qth_min, ctl_v1->qth_max,
660668
ctl_v1->Wlog, ctl_v1->Scell_log, NULL))
661669
return -EINVAL;
@@ -672,14 +680,12 @@ static int sfq_change(struct Qdisc *sch, struct nlattr *opt,
672680
headdrop = q->headdrop;
673681
maxdepth = q->maxdepth;
674682
maxflows = q->maxflows;
675-
perturb_period = q->perturb_period;
676683
quantum = q->quantum;
677684
flags = q->flags;
678685

679686
/* update and validate configuration */
680687
if (ctl->quantum)
681688
quantum = ctl->quantum;
682-
perturb_period = ctl->perturb_period * HZ;
683689
if (ctl->flows)
684690
maxflows = min_t(u32, ctl->flows, SFQ_MAX_FLOWS);
685691
if (ctl->divisor) {

0 commit comments

Comments
 (0)