On Tue, Aug 4, 2026 at 6:11 PM Xiong Weimin <[email protected]> wrote:
>
> Validate the AF_XDP queue index before dereferencing the receive or
> send queue arrays in virtnet_xsk_pool_enable().  This keeps an out of
> range queue id from reaching vi->rq[qid] while checking page_pool.
>
> Signed-off-by: Xiong Weimin <[email protected]>

Fixes: 24fbd3967f3f ("virtio_net: add page_pool support for buffer allocation")

Reviewed-by: Jason Xing <[email protected]>

Thanks!

> ---
>  drivers/net/virtio_net.c | 6 +++---
>  1 file changed, 3 insertions(+), 3 deletions(-)
>
> diff --git a/drivers/net/virtio_net.c b/drivers/net/virtio_net.c
> index 3e2a5876c..6160aa8ba 100644
> --- a/drivers/net/virtio_net.c
> +++ b/drivers/net/virtio_net.c
> @@ -5896,15 +5896,15 @@ static int virtnet_xsk_pool_enable(struct net_device 
> *dev,
>         if (vi->hdr_len > xsk_pool_get_headroom(pool))
>                 return -EINVAL;
>
> +       if (qid >= vi->curr_queue_pairs)
> +               return -EINVAL;
> +
>         /* In big_packets mode, xdp cannot work, so there is no need to
>          * initialize xsk of rq.
>          */
>         if (!vi->rq[qid].page_pool)
>                 return -ENOENT;
>
> -       if (qid >= vi->curr_queue_pairs)
> -               return -EINVAL;
> -
>         sq = &vi->sq[qid];
>         rq = &vi->rq[qid];
>
> --
> 2.43.0
>
>

Reply via email to