The jumbo Rx path keeps its data in buffer_info->page rather than the
skb, which is only a shell. Previously data beyond the end of the skb
allocation would be dumped. The jumbo path would at best dump useless
garbage. At worst it would dump arbitrary kernel memory. This OOB read
is only reachable when page size is >16K and MTU is >1518.

Dump the page instead when it exists. Skip dumping the shell skb left
behind when a jumbo slot is cleaned.

Signed-off-by: Matt Vollrath <[email protected]>
Fixes: f0c5dadff3fb ("e1000e: fix panic while dumping packets on Tx hang with 
IOMMU")
Cc: [email protected]
Assisted-by: Claude:claude-5-fable
---
 drivers/net/ethernet/intel/e1000e/netdev.c | 17 ++++++++++++++++-
 1 file changed, 16 insertions(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/intel/e1000e/netdev.c 
b/drivers/net/ethernet/intel/e1000e/netdev.c
index 599600ad695c..47ff3c6ab451 100644
--- a/drivers/net/ethernet/intel/e1000e/netdev.c
+++ b/drivers/net/ethernet/intel/e1000e/netdev.c
@@ -465,8 +465,23 @@ static void e1000e_dump(struct e1000_adapter *adapter)
                                        (unsigned long long)buffer_info->dma,
                                        buffer_info->skb, next_desc);
 
+                               /* Jumbo buffers land in the page; a cleaned
+                                * jumbo slot keeps only its small shell skb
+                                * until it is refilled, so only dump an skb
+                                * that can hold a whole buffer.
+                                */
                                if (netif_msg_pktdata(adapter) &&
-                                   buffer_info->skb)
+                                   buffer_info->page)
+                                       print_hex_dump(KERN_INFO, "",
+                                                      DUMP_PREFIX_ADDRESS, 16,
+                                                      1,
+                                                      
page_address(buffer_info->page),
+                                                      adapter->rx_buffer_len,
+                                                      true);
+                               else if (netif_msg_pktdata(adapter) &&
+                                        buffer_info->skb &&
+                                        skb_tailroom(buffer_info->skb) >=
+                                        adapter->rx_buffer_len)
                                        print_hex_dump(KERN_INFO, "",
                                                       DUMP_PREFIX_ADDRESS, 16,
                                                       1,
-- 
2.43.0

Reply via email to