mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net] net: fix NULL dereference in skb realloc fault injection devname filter
@ 2026-09-30 12:20 Haishuang Yan
  2026-10-01 18:28 ` [PATCH net v2] " Haishuang Yan
  2026-10-02 10:30 ` [PATCH net] " Breno Leitao
  0 siblings, 2 replies; 4+ messages in thread
From: Haishuang Yan @ 2026-09-30 12:20 UTC (permalink / raw)
  To: netdev
  Cc: Breno Leitao, David S . Miller, Eric Dumazet, Jakub Kicinski,
	Paolo Abeni, Simon Horman, Guillaume Nault, Akinobu Mita,
	linux-kernel, Haishuang Yan

When a device name filter is set in
/sys/kernel/debug/fail_skb_realloc/devname, should_fail_net_realloc_skb()
compares it with skb->dev->name without checking skb->dev first.

skb_might_realloc() is called from pskb_may_pull(), __skb_cow() and
pskb_trim(), which also run on skbs that are not associated with a
device. One example is a netlink broadcast to a listener with a socket
filter attached, which goes through sk_filter_trim_cap(). With the
filter set, such an skb makes the kernel oops:

  KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]
  pc : strncmp+0x50/0xf0
  lr : skb_might_realloc+0x58/0xa0
  Call trace:
   strncmp+0x50/0xf0 (P)
   skb_might_realloc+0x58/0xa0
   sk_filter_trim_cap+0x6a0/0x928
   do_one_broadcast+0x35c/0xb20
   netlink_broadcast_filtered+0x1a4/0x328
   netlink_sendmsg+0x724/0xa58

An skb without a device cannot match the configured device name, so do
not inject a reallocation for it.

Fixes: 12079a59ce52 ("net: Implement fault injection forcing skb reallocation")
Assisted-by: LLM
Signed-off-by: Haishuang Yan <yanhaishuang@cmss.chinamobile.com>
---
 net/core/skb_fault_injection.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/net/core/skb_fault_injection.c b/net/core/skb_fault_injection.c
index 4235db6bdfad..7f8315c864c8 100644
--- a/net/core/skb_fault_injection.c
+++ b/net/core/skb_fault_injection.c
@@ -19,8 +19,8 @@ static bool should_fail_net_realloc_skb(struct sk_buff *skb)
 	struct net_device *net = skb->dev;
 
 	if (skb_realloc.filtered &&
-	    strncmp(net->name, skb_realloc.devname, IFNAMSIZ))
-		/* device name filter set, but names do not match */
+	    (!net || strncmp(net->name, skb_realloc.devname, IFNAMSIZ)))
+		/* device name filter set, but no device or names do not match */
 		return false;
 
 	if (!should_fail(&skb_realloc.attr, 1))
-- 
2.43.0




^ permalink raw reply	[flat|nested] 4+ messages in thread

* [PATCH net v2] net: fix NULL dereference in skb realloc fault injection devname filter
  2026-09-30 12:20 [PATCH net] net: fix NULL dereference in skb realloc fault injection devname filter Haishuang Yan
@ 2026-10-01 18:28 ` Haishuang Yan
  2026-10-02 10:30 ` [PATCH net] " Breno Leitao
  1 sibling, 0 replies; 4+ messages in thread
From: Haishuang Yan @ 2026-10-01 18:28 UTC (permalink / raw)
  To: netdev
  Cc: Breno Leitao, David S . Miller, Eric Dumazet, Jakub Kicinski,
	Paolo Abeni, Simon Horman, Guillaume Nault, Akinobu Mita,
	linux-kernel, Haishuang Yan

When a device name filter is set in
/sys/kernel/debug/fail_skb_realloc/devname, should_fail_net_realloc_skb()
compares it with skb->dev->name without checking skb->dev first.

skb_might_realloc() is called from pskb_may_pull(), __skb_cow() and
pskb_trim(), which also run on skbs that are not associated with a
device. One example is a netlink broadcast to a listener with a socket
filter attached, which goes through sk_filter_trim_cap(). With the
filter set, such an skb makes the kernel oops:

  KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]
  pc : strncmp+0x50/0xf0
  lr : skb_might_realloc+0x58/0xa0
  Call trace:
   strncmp+0x50/0xf0 (P)
   skb_might_realloc+0x58/0xa0
   sk_filter_trim_cap+0x6a0/0x928
   do_one_broadcast+0x35c/0xb20
   netlink_broadcast_filtered+0x1a4/0x328
   netlink_sendmsg+0x724/0xa58

The fault is meant to be injected on network interfaces, so skip skbs
that are not associated with a device. Without a device name filter,
such skbs are no longer reallocated either.

Fixes: 12079a59ce52 ("net: Implement fault injection forcing skb reallocation")
Suggested-by: Breno Leitao <leitao@debian.org>
Assisted-by: LLM
Signed-off-by: Haishuang Yan <yanhaishuang@cmss.chinamobile.com>
---
v2:
- Return early for skbs without a device, as suggested by Breno. Such
  skbs are now skipped whether or not a device name filter is set.
- Tested on arm64 (QEMU) with KASAN: the netlink broadcast reproducer no
  longer oopses with devname set, the devname filter still injects on
  the selected device, and without a filter skbs without a device are
  skipped while skbs on a device are still reallocated.

v1: https://lore.kernel.org/netdev/20260930122013.110284-1-yanhaishuang@cmss.chinamobile.com/

 net/core/skb_fault_injection.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/net/core/skb_fault_injection.c b/net/core/skb_fault_injection.c
index 4235db6bdfad..63a397f76113 100644
--- a/net/core/skb_fault_injection.c
+++ b/net/core/skb_fault_injection.c
@@ -18,6 +18,9 @@ static bool should_fail_net_realloc_skb(struct sk_buff *skb)
 {
 	struct net_device *net = skb->dev;
 
+	if (!net)
+		return false;
+
 	if (skb_realloc.filtered &&
 	    strncmp(net->name, skb_realloc.devname, IFNAMSIZ))
 		/* device name filter set, but names do not match */
-- 
2.43.0




^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net] net: fix NULL dereference in skb realloc fault injection devname filter
  2026-10-02 10:30 ` [PATCH net] " Breno Leitao
@ 2026-10-01 18:44   ` Haishuang Yan
  0 siblings, 0 replies; 4+ messages in thread
From: Haishuang Yan @ 2026-10-01 18:44 UTC (permalink / raw)
  To: Breno Leitao
  Cc: netdev, David S . Miller, Eric Dumazet, Jakub Kicinski,
	Paolo Abeni, Simon Horman, Guillaume Nault, Akinobu Mita,
	linux-kernel

On Thu, Oct 01, 2026 at 10:30, Breno Leitao wrote:
> I think something like this untested approach reads better:
>
> +	if (!net)
> +		return false;
> +

Thanks for the review, Breno. Agreed, this reads better, and the fault
is meant for skbs on a network device anyway.

I sent v2 with your suggestion and added aV Suggested-by tag:
https://lore.kernel.org/netdev/20261001182813.353004-1-yanhaishuang@cmss.chinamobile.com

Thanks,
Haishuang



^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH net] net: fix NULL dereference in skb realloc fault injection devname filter
  2026-09-30 12:20 [PATCH net] net: fix NULL dereference in skb realloc fault injection devname filter Haishuang Yan
  2026-10-01 18:28 ` [PATCH net v2] " Haishuang Yan
@ 2026-10-02 10:30 ` Breno Leitao
  2026-10-01 18:44   ` Haishuang Yan
  1 sibling, 1 reply; 4+ messages in thread
From: Breno Leitao @ 2026-10-02 10:30 UTC (permalink / raw)
  To: Haishuang Yan
  Cc: netdev, David S . Miller, Eric Dumazet, Jakub Kicinski,
	Paolo Abeni, Simon Horman, Guillaume Nault, Akinobu Mita,
	linux-kernel

> --- a/net/core/skb_fault_injection.c
> +++ b/net/core/skb_fault_injection.c
> @@ -19,8 +19,8 @@ static bool should_fail_net_realloc_skb(struct sk_buff *skb)
>  	struct net_device *net = skb->dev;
>  
>  	if (skb_realloc.filtered &&
> -	    strncmp(net->name, skb_realloc.devname, IFNAMSIZ))
> -		/* device name filter set, but names do not match */
> +	    (!net || strncmp(net->name, skb_realloc.devname, IFNAMSIZ)))
> +		/* device name filter set, but no device or names do not match */
>  		return false;
>  
>  	if (!should_fail(&skb_realloc.attr, 1))

I think something like this untested approach reads better:

diff --git a/net/core/skb_fault_injection.c b/net/core/skb_fault_injection.c
index 4235db6bdfad55..63a397f761133c 100644
--- a/net/core/skb_fault_injection.c
+++ b/net/core/skb_fault_injection.c
@@ -18,6 +18,9 @@ static bool should_fail_net_realloc_skb(struct sk_buff *skb)
 {
        struct net_device *net = skb->dev;

+       if (!net)
+               return false;
+
        if (skb_realloc.filtered &&
            strncmp(net->name, skb_realloc.devname, IFNAMSIZ))
                /* device name filter set, but names do not match */



^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2026-10-02 13:48 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-30 12:20 [PATCH net] net: fix NULL dereference in skb realloc fault injection devname filter Haishuang Yan
2026-10-01 18:28 ` [PATCH net v2] " Haishuang Yan
2026-10-02 10:30 ` [PATCH net] " Breno Leitao
2026-10-01 18:44   ` Haishuang Yan

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®