aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorVladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru>2025-07-16 10:28:53 +0300
committerJason Wang <jasowang@redhat.com>2025-07-21 10:21:28 +0800
commit3f9f6299a1bc46ff462142c7398a5953e3640cc2 (patch)
tree6350f1f82fa890114bf7860b5d6f9db00194a8d3
parente82989544e38062beeeaad88c175afbeed0400f8 (diff)
downloadqemu-3f9f6299a1bc46ff462142c7398a5953e3640cc2.zip
qemu-3f9f6299a1bc46ff462142c7398a5953e3640cc2.tar.gz
qemu-3f9f6299a1bc46ff462142c7398a5953e3640cc2.tar.bz2
net/tap: drop too small packets
Theoretically tap_read_packet() may return size less than s->host_vnet_hdr_len, and next, we'll work with negative size (in case of !s->using_vnet_hdr). Let's avoid it. Don't proceed with size == s->host_vnet_hdr_len as well in case of !s->using_vnet_hdr, it doesn't make sense. Tested-by: Lei Yang <leiyang@redhat.com> Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru> Signed-off-by: Jason Wang <jasowang@redhat.com>
-rw-r--r--net/tap.c5
1 files changed, 5 insertions, 0 deletions
diff --git a/net/tap.c b/net/tap.c
index 23536c0..2a85936 100644
--- a/net/tap.c
+++ b/net/tap.c
@@ -190,6 +190,11 @@ static void tap_send(void *opaque)
break;
}
+ if (s->host_vnet_hdr_len && size <= s->host_vnet_hdr_len) {
+ /* Invalid packet */
+ break;
+ }
+
if (s->host_vnet_hdr_len && !s->using_vnet_hdr) {
buf += s->host_vnet_hdr_len;
size -= s->host_vnet_hdr_len;