On Sun, Sep 27, 2026 at 6:31 PM Weiming Shi <[email protected]> wrote: > > skb_gso_transport_seglen() derives the TCP header length with > tcp_hdrlen() or inner_tcp_hdrlen(). Both helpers dereference transport > header metadata without validating it first. > > A TUN user can supply a TCP GSO packet without NEEDS_CSUM and with an > invalid IP header. The skb remains GSO while transport_header keeps the > unset sentinel. TBF and police can then reach the length validator and > read tcp->doff outside the skb head.
Do you realize this leaves non-TCP GSO broken with unset transport_header ? Please fix tun instead of adding numerous workarounds in our fast paths. __virtio_net_hdr_to_skb() needs hardening instead. virtio_net/tun/af_packet MUST not feed 'gso' packets without transport header being set, among other things. pw-bot: rejected

