Received: by 10.213.65.68 with SMTP id h4csp504173imn; Fri, 16 Mar 2018 09:45:31 -0700 (PDT) X-Google-Smtp-Source: AG47ELvX8vnvIsKyAl+gsaIt5Gnf4dHlC1m5kbp1adueU7LJT9hmcVeQWVvgtSvqzK/bxhNpVJYe X-Received: by 10.98.170.13 with SMTP id e13mr2115152pff.113.1521218731246; Fri, 16 Mar 2018 09:45:31 -0700 (PDT) ARC-Seal: i=1; a=rsa-sha256; t=1521218731; cv=none; d=google.com; s=arc-20160816; b=OApyz7RB6pe3hp+01nYNitHxcTJFzMtfhymD2z2R6BhGosMMmZS1FRFDSZufm9P/37 YfJ49E3Z2T1RqudRIRpx5MhBxcrr4C9BHToZj71Ut02K5aLDqsgY0VLS3MruQLsHhzRC wp4ZhJOL1uK44O8MswG90P9+BvFVaWlZ/2LZ4qrpEgpZBZTESlsRxUoUa7e51BL616EV JlE5vdHonj82nz80gr5YB68U7bgBq3Z/F4N5/ZlUallf1kywdHkWRzU+xIUNt2IPMXM3 v8Z301Z0fn8hH8FIrAJBrDJNzC4x8fKYXBflONMgwSJTJN2DSvukQh/Hb9JEgVZ6Gb7/ /BsA== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20160816; h=list-id:precedence:sender:mime-version:user-agent:references :in-reply-to:message-id:date:subject:cc:to:from :arc-authentication-results; bh=txbLnoIWiGhyJDlaqKrzfPVoAebu74T3mf3qusmgkoI=; b=uiznLpqyf1ZmlgzXXKeb8zhthHrp2ydAYQl5ZyOz7BBXUyVjNgDxXkH8kpzneh2gyx kg3Ejwq/srgtjSazsnXRV7yVTqO6vjWkM+eW1OblQUU4kFE1kwOcwiWNIx6WnRE5MNva 6mHdxv25kyYyX0s52b1D5MkjZwkMcOdPfy6FlC1YEsRlEajiVJ7Os5eORgHJjrt7PSOQ jt1J80ikGRzI7bDcP4zQGplTQ0wwcf2ROc5nySQMa3Bzhl2VBrb/S5JACIWB7vK5HJX4 TmxbbPLssycpqjhLtbanrHxVipyJxQO4NCLrhw5qPxEV6OtdvUpICFmYMh1O9f3xnyda /6Fw== ARC-Authentication-Results: i=1; mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Return-Path: Received: from vger.kernel.org (vger.kernel.org. [209.132.180.67]) by mx.google.com with ESMTP id ba10-v6si6422498plb.5.2018.03.16.09.45.17; Fri, 16 Mar 2018 09:45:31 -0700 (PDT) Received-SPF: pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) client-ip=209.132.180.67; Authentication-Results: mx.google.com; spf=pass (google.com: best guess record for domain of linux-kernel-owner@vger.kernel.org designates 209.132.180.67 as permitted sender) smtp.mailfrom=linux-kernel-owner@vger.kernel.org Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1753327AbeCPQne (ORCPT + 99 others); Fri, 16 Mar 2018 12:43:34 -0400 Received: from mail.linuxfoundation.org ([140.211.169.12]:40176 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S934251AbeCPPgO (ORCPT ); Fri, 16 Mar 2018 11:36:14 -0400 Received: from localhost (LFbn-1-12247-202.w90-92.abo.wanadoo.fr [90.92.61.202]) by mail.linuxfoundation.org (Postfix) with ESMTPSA id CC1B91080; Fri, 16 Mar 2018 15:36:13 +0000 (UTC) From: Greg Kroah-Hartman To: linux-kernel@vger.kernel.org Cc: Greg Kroah-Hartman , stable@vger.kernel.org, Yossef Efraim , Steffen Klassert , Sasha Levin Subject: [PATCH 4.14 054/109] xfrm: Fix xfrm_replay_overflow_offload_esn Date: Fri, 16 Mar 2018 16:23:23 +0100 Message-Id: <20180316152332.896959188@linuxfoundation.org> X-Mailer: git-send-email 2.16.2 In-Reply-To: <20180316152329.844663293@linuxfoundation.org> References: <20180316152329.844663293@linuxfoundation.org> User-Agent: quilt/0.65 X-stable: review MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Sender: linux-kernel-owner@vger.kernel.org Precedence: bulk List-ID: X-Mailing-List: linux-kernel@vger.kernel.org 4.14-stable review patch. If anyone has any objections, please let me know. ------------------ From: Yossef Efraim [ Upstream commit 0ba23a211360af7b6658e4fcfc571970bbbacc55 ] In case of wrap around, replay_esn->oseq_hi is not updated before it is tested for it's actual value, leading function to fail with overflow indication and packets being dropped. This patch updates replay_esn->oseq_hi in the right place. Fixes: d7dbefc45cf5 ("xfrm: Add xfrm_replay_overflow functions for offloading") Signed-off-by: Yossef Efraim Signed-off-by: Steffen Klassert Signed-off-by: Sasha Levin Signed-off-by: Greg Kroah-Hartman --- net/xfrm/xfrm_replay.c | 3 +-- 1 file changed, 1 insertion(+), 2 deletions(-) --- a/net/xfrm/xfrm_replay.c +++ b/net/xfrm/xfrm_replay.c @@ -666,7 +666,7 @@ static int xfrm_replay_overflow_offload_ if (unlikely(oseq < replay_esn->oseq)) { XFRM_SKB_CB(skb)->seq.output.hi = ++oseq_hi; xo->seq.hi = oseq_hi; - + replay_esn->oseq_hi = oseq_hi; if (replay_esn->oseq_hi == 0) { replay_esn->oseq--; replay_esn->oseq_hi--; @@ -678,7 +678,6 @@ static int xfrm_replay_overflow_offload_ } replay_esn->oseq = oseq; - replay_esn->oseq_hi = oseq_hi; if (xfrm_aevent_is_on(net)) x->repl->notify(x, XFRM_REPLAY_UPDATE);