On Mon, Sep 14, 2026 at 2:04 AM Inbal Schussheim <[email protected]> wrote: > > Exclude old ACKs before SND.UNA from the tcp fast path > as well as ACKs after SND.NXT. > > Such ACKs will fall through to the slow path, where tcp_ack() > performs the appropriate validation and challenge ACK handling > according to RFC5961 and Commit 3d501dd326fb1c7 ("tcp: do not > accept ACK of bytes we never sent"). > > This prevents old ACKs from being accepted > or modifying connection state as part of the fast path before > appropriate ACK validation is applied. > In particular, this prevents payload carried by a segment with > an excessively old ACK from advancing RCV.NXT before the ACK > is rejected. > > Fixes: 31770e34e43d ("tcp: Revert "tcp: remove header prediction"") > Reported-by: Amit Klein <[email protected]> > Reported-by: Tamir Shahar <[email protected]> > Reported-by: Inbal Schussheim <[email protected]>
nit: (no need for a new version) You are the patch author, the " Reported-by: Inbal Schussheim <[email protected]>" is redundant with Signed-off-by from the same person. Reviewed-by: Eric Dumazet <[email protected]> > Suggested-by: Eric Dumazet <[email protected]> > Cc: [email protected] > Signed-off-by: Inbal Schussheim <[email protected]> > --- > net/ipv4/tcp_input.c | 3 ++- > 1 file changed, 2 insertions(+), 1 deletion(-) > > diff --git a/net/ipv4/tcp_input.c b/net/ipv4/tcp_input.c > index daff93d51342..03d317a58132 100644 > --- a/net/ipv4/tcp_input.c > +++ b/net/ipv4/tcp_input.c > @@ -6490,6 +6490,7 @@ static bool tcp_validate_incoming(struct sock *sk, > struct sk_buff *skb, > * or pure receivers (this means either the sequence number or the ack > * value must stay constant) > * - Unexpected TCP option. > + * - ACK sequence number is outside [SND.UNA, SND.NXT]. > * > * When these conditions are not satisfied it drops into a standard > * receive procedure patterned after RFC793 to handle all cases. > @@ -6539,7 +6540,7 @@ void tcp_rcv_established(struct sock *sk, struct > sk_buff *skb) > > if ((tcp_flag_word(th) & TCP_HP_BITS) == tp->pred_flags && > TCP_SKB_CB(skb)->seq == tp->rcv_nxt && > - !after(TCP_SKB_CB(skb)->ack_seq, tp->snd_nxt)) { > + between(TCP_SKB_CB(skb)->ack_seq, tp->snd_una, tp->snd_nxt)) { > int tcp_header_len = tp->tcp_header_len; > s32 delta = 0; > int flag = 0; > -- > 2.43.0 >
