From owner-freebsd-bugs@FreeBSD.ORG Fri Aug 26 15:00:25 2005 Return-Path: X-Original-To: freebsd-bugs@hub.freebsd.org Delivered-To: freebsd-bugs@hub.freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id F16FB16A467 for ; Fri, 26 Aug 2005 15:00:24 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (freefall.freebsd.org [216.136.204.21]) by mx1.FreeBSD.org (Postfix) with ESMTP id 7298243D45 for ; Fri, 26 Aug 2005 15:00:24 +0000 (GMT) (envelope-from gnats@FreeBSD.org) Received: from freefall.freebsd.org (gnats@localhost [127.0.0.1]) by freefall.freebsd.org (8.13.3/8.13.3) with ESMTP id j7QF0Olh098867 for ; Fri, 26 Aug 2005 15:00:24 GMT (envelope-from gnats@freefall.freebsd.org) Received: (from gnats@localhost) by freefall.freebsd.org (8.13.3/8.13.1/Submit) id j7QF0O7T098854; Fri, 26 Aug 2005 15:00:24 GMT (envelope-from gnats) Resent-Date: Fri, 26 Aug 2005 15:00:24 GMT Resent-Message-Id: <200508261500.j7QF0O7T098854@freefall.freebsd.org> Resent-From: FreeBSD-gnats-submit@FreeBSD.org (GNATS Filer) Resent-To: freebsd-bugs@FreeBSD.org Resent-Reply-To: FreeBSD-gnats-submit@FreeBSD.org, Ming Fu Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id 8C77916A41F for ; Fri, 26 Aug 2005 14:58:35 +0000 (GMT) (envelope-from nobody@FreeBSD.org) Received: from www.freebsd.org (www.freebsd.org [216.136.204.117]) by mx1.FreeBSD.org (Postfix) with ESMTP id 59D0E43D45 for ; Fri, 26 Aug 2005 14:58:35 +0000 (GMT) (envelope-from nobody@FreeBSD.org) Received: from www.freebsd.org (localhost [127.0.0.1]) by www.freebsd.org (8.13.1/8.13.1) with ESMTP id j7QEwZG1022936 for ; Fri, 26 Aug 2005 14:58:35 GMT (envelope-from nobody@www.freebsd.org) Received: (from nobody@localhost) by www.freebsd.org (8.13.1/8.13.1/Submit) id j7QEwZrw022935; Fri, 26 Aug 2005 14:58:35 GMT (envelope-from nobody) Message-Id: <200508261458.j7QEwZrw022935@www.freebsd.org> Date: Fri, 26 Aug 2005 14:58:35 GMT From: Ming Fu To: freebsd-gnats-submit@FreeBSD.org X-Send-Pr-Version: www-2.3 Cc: Subject: kern/85320: possible depletion of kernel stack in ip_gre.c when net.isr.enable = 1 X-BeenThere: freebsd-bugs@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: Bug reports List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Fri, 26 Aug 2005 15:00:25 -0000 >Number: 85320 >Category: kern >Synopsis: possible depletion of kernel stack in ip_gre.c when net.isr.enable = 1 >Confidential: no >Severity: serious >Priority: high >Responsible: freebsd-bugs >State: open >Quarter: >Keywords: >Date-Required: >Class: sw-bug >Submitter-Id: current-users >Arrival-Date: Fri Aug 26 15:00:23 GMT 2005 >Closed-Date: >Last-Modified: >Originator: Ming Fu >Release: FreeBSD 5.x >Organization: Borderware Technologies Inc >Environment: FreeBSD home.borderware.com 5.4-RELEASE FreeBSD 5.4-RELEASE #1: Tue May 31 10:17:34 EDT 2005 fming@home.borderware.com >Description: when net.isr.enable = 1 and a GRE packet gets into the ip_gre2(), its gre header is stripped and sent to netisr_dispatch() for ip_input() processing again. As the net.isr.enable is 1, the packet will be delivered to ip_input directly instead of put in the queue. If someone create a packet consists of repeated ip and gre header, ip hdr : gre hdr : ip hdr : gre hdr : ...... repeat a few hundred times. it can cause a loop around ip_gre->ip_gre2->netisr_dispatch->ip_input->ip_gre ..., and deplete the kernel stack. >How-To-Repeat: send a packet with a few hundred repeated IP and GRE header to a freebsd 5.x with gre configured. >Fix: Index: ip_gre.c =================================================================== RCS file: /usr/cvsroot/freebsd/src/sys/netinet/ip_gre.c,v retrieving revision 1.20 diff -u -r1.20 ip_gre.c --- ip_gre.c 1 Aug 2005 08:14:21 -0000 1.20 +++ ip_gre.c 26 Aug 2005 14:40:32 -0000 @@ -223,7 +223,7 @@ m->m_pkthdr.rcvif = GRE2IFP(sc); - netisr_dispatch(isr, m); + netisr_queue(isr, m); return (1); /* packet is done, no further processing needed */ } >Release-Note: >Audit-Trail: >Unformatted: