Commit ee7f9bb9320a for kernel

commit ee7f9bb9320add61f7b367d7e6cd55e3a3a4d65d
Author: Sungmin Kang <726ksm@gmail.com>
Date:   Sat Jul 18 16:36:30 2026 +0900

    net: slip: serialize receive against buffer reallocation

    sl_realloc_bufs() replaces rbuff and updates buffsize while holding
    sl->lock. slip_receive_buf() reads those fields and writes through rbuff
    without holding the lock.

    An MTU change can therefore race with receive processing. An MTU shrink
    can expose the new smaller rbuff with the old larger bound, causing an
    out-of-bounds write. A receive callback which already loaded the old
    rbuff can instead continue writing after that buffer has been freed.

    Serialize receive processing with sl_realloc_bufs() by holding sl->lock
    while consuming each receive batch.

    Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
    Cc: stable@vger.kernel.org
    Signed-off-by: Sungmin Kang <726ksm@gmail.com>
    Link: https://patch.msgid.link/20260718073631.1674-1-726ksm@gmail.com
    Signed-off-by: Jakub Kicinski <kuba@kernel.org>

diff --git a/drivers/net/slip/slip.c b/drivers/net/slip/slip.c
index 820e1a8fc956..faae711cf793 100644
--- a/drivers/net/slip/slip.c
+++ b/drivers/net/slip/slip.c
@@ -693,6 +693,8 @@ static void slip_receive_buf(struct tty_struct *tty, const u8 *cp, const u8 *fp,
 	if (!sl || sl->magic != SLIP_MAGIC || !netif_running(sl->dev))
 		return;

+	spin_lock_bh(&sl->lock);
+
 	/* Read the characters out of the buffer */
 	while (count--) {
 		if (fp && *fp++) {
@@ -708,6 +710,8 @@ static void slip_receive_buf(struct tty_struct *tty, const u8 *cp, const u8 *fp,
 #endif
 			slip_unesc(sl, *cp++);
 	}
+
+	spin_unlock_bh(&sl->lock);
 }

 /************************************