--- zzzz-none-000/linux-4.4.60/net/ipv4/esp4.c 2017-04-08 07:53:53.000000000 +0000 +++ scorpion-1750e-727/linux-4.4.60/net/ipv4/esp4.c 2021-02-04 17:41:59.000000000 +0000 @@ -150,6 +150,7 @@ int assoclen; int extralen; __be64 seqno; + bool nosupp_sg; /* skb is pure payload to encrypt */ @@ -157,6 +158,12 @@ alen = crypto_aead_authsize(aead); ivlen = crypto_aead_ivsize(aead); + nosupp_sg = crypto_tfm_alg_flags(&aead->base) & CRYPTO_ALG_NOSUPP_SG; + if (nosupp_sg && skb_linearize(skb)) { + err = -ENOMEM; + goto error; + } + tfclen = 0; if (x->tfcpad) { struct xfrm_dst *dst = (struct xfrm_dst *)skb_dst(skb); @@ -430,6 +437,7 @@ u8 *iv; struct scatterlist *sg; int err = -EINVAL; + bool nosupp_sg; if (!pskb_may_pull(skb, sizeof(*esph) + ivlen)) goto out; @@ -437,6 +445,12 @@ if (elen <= 0) goto out; + nosupp_sg = crypto_tfm_alg_flags(&aead->base) & CRYPTO_ALG_NOSUPP_SG; + if (nosupp_sg && skb_linearize(skb)) { + err = -ENOMEM; + goto out; + } + err = skb_cow_data(skb, 0, &trailer); if (err < 0) goto out;