CVE-2026-74269: bnxt: fix head underflow on XDP head-grow
In the Linux kernel, the following vulnerability has been resolved:
bnxt: fix head underflow on XDP head-grow
The xdp.py test testxdpnativeadjstheadgrowdata crashes when run on a bnxt machine (and also crashes in NIPA).
It seems that the bug is an underflow in bnxtrxmultipageskb, which builds the skb head:
napibuildskb(dataptr - bp->rxoffset, rxr->rxpagesize);
The problem with this expression is that in page mode, rxoffset is:
bp->rxoffset = NETIPALIGN + XDPPACKETHEADROOM;
Which evaluates (at least on x8664) to 258.
The test testxdpnativeadjstheadgrowdata tests a case where the head is adjusted by -256.
When this test runs, dataptr is shifted to fragstart + 2 (where fragstart = pageaddress(page) + offset).
Then, bnxtrxmultipageskb is invoked and the napibuildskb expression subtracts 258, landing at an address before fragstart. This could be either the previous fragment or the previous physical page when the offset is < 256 (e.g. if the fragment started at offset 0).
When the skb is freed, the page pool fragment reference is dropped on either the wrong page or the wrong frag of the right page. In either case, the corrupted reference count can lead to the page being prematurely recycled while still in use. Once (incorrectly) recycled, it can be handed out again and on driver teardown this would result in a double free.
The commit under fixes updated this code to handle the case where the native page size is >= 64k, but it unintentionally broke the head grow case.
To fix this, add an offset field to struct bnxtswrxbd, mirroring the existing offset field in struct bnxtswrxaggbd. Populate it on allocation and preserve it on reuse.
In bnxtrxmultipageskb, use the newly added offset field to compute the fragment start and pass that to napibuildskb. Adjust the layout with skbreserve.
There are two cases, the non-adjustment case and the adjustment case.
In both cases, the skb is built at pageaddress(page) + offset to account for the case where the native page size >= 64K and skbreserve is called with dataptr - (pageaddress(page) + offset). That difference equals bp->rxoffset when dataptr was not moved, or bp->rxoffset + xdpadjust when XDP adjusted the head.
Re-running the failing test with this commit applied causes the test to run successfully to completion.
The other rxskbfunc implementations don't have this issue.