* [PATCH net] net: fix NULL dereference in skb realloc fault injection devname filter
@ 2026-09-30 12:20 Haishuang Yan
2026-10-01 18:28 ` [PATCH net v2] " Haishuang Yan
2026-10-02 10:30 ` [PATCH net] " Breno Leitao
0 siblings, 2 replies; 4+ messages in thread
From: Haishuang Yan @ 2026-09-30 12:20 UTC (permalink / raw)
To: netdev
Cc: Breno Leitao, David S . Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Simon Horman, Guillaume Nault, Akinobu Mita,
linux-kernel, Haishuang Yan
When a device name filter is set in
/sys/kernel/debug/fail_skb_realloc/devname, should_fail_net_realloc_skb()
compares it with skb->dev->name without checking skb->dev first.
skb_might_realloc() is called from pskb_may_pull(), __skb_cow() and
pskb_trim(), which also run on skbs that are not associated with a
device. One example is a netlink broadcast to a listener with a socket
filter attached, which goes through sk_filter_trim_cap(). With the
filter set, such an skb makes the kernel oops:
KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]
pc : strncmp+0x50/0xf0
lr : skb_might_realloc+0x58/0xa0
Call trace:
strncmp+0x50/0xf0 (P)
skb_might_realloc+0x58/0xa0
sk_filter_trim_cap+0x6a0/0x928
do_one_broadcast+0x35c/0xb20
netlink_broadcast_filtered+0x1a4/0x328
netlink_sendmsg+0x724/0xa58
An skb without a device cannot match the configured device name, so do
not inject a reallocation for it.
Fixes: 12079a59ce52 ("net: Implement fault injection forcing skb reallocation")
Assisted-by: LLM
Signed-off-by: Haishuang Yan <yanhaishuang@cmss.chinamobile.com>
---
net/core/skb_fault_injection.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/core/skb_fault_injection.c b/net/core/skb_fault_injection.c
index 4235db6bdfad..7f8315c864c8 100644
--- a/net/core/skb_fault_injection.c
+++ b/net/core/skb_fault_injection.c
@@ -19,8 +19,8 @@ static bool should_fail_net_realloc_skb(struct sk_buff *skb)
struct net_device *net = skb->dev;
if (skb_realloc.filtered &&
- strncmp(net->name, skb_realloc.devname, IFNAMSIZ))
- /* device name filter set, but names do not match */
+ (!net || strncmp(net->name, skb_realloc.devname, IFNAMSIZ)))
+ /* device name filter set, but no device or names do not match */
return false;
if (!should_fail(&skb_realloc.attr, 1))
--
2.43.0
^ permalink raw reply [flat|nested] 4+ messages in thread
* [PATCH net v2] net: fix NULL dereference in skb realloc fault injection devname filter
2026-09-30 12:20 [PATCH net] net: fix NULL dereference in skb realloc fault injection devname filter Haishuang Yan
@ 2026-10-01 18:28 ` Haishuang Yan
2026-10-02 10:30 ` [PATCH net] " Breno Leitao
1 sibling, 0 replies; 4+ messages in thread
From: Haishuang Yan @ 2026-10-01 18:28 UTC (permalink / raw)
To: netdev
Cc: Breno Leitao, David S . Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Simon Horman, Guillaume Nault, Akinobu Mita,
linux-kernel, Haishuang Yan
When a device name filter is set in
/sys/kernel/debug/fail_skb_realloc/devname, should_fail_net_realloc_skb()
compares it with skb->dev->name without checking skb->dev first.
skb_might_realloc() is called from pskb_may_pull(), __skb_cow() and
pskb_trim(), which also run on skbs that are not associated with a
device. One example is a netlink broadcast to a listener with a socket
filter attached, which goes through sk_filter_trim_cap(). With the
filter set, such an skb makes the kernel oops:
KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]
pc : strncmp+0x50/0xf0
lr : skb_might_realloc+0x58/0xa0
Call trace:
strncmp+0x50/0xf0 (P)
skb_might_realloc+0x58/0xa0
sk_filter_trim_cap+0x6a0/0x928
do_one_broadcast+0x35c/0xb20
netlink_broadcast_filtered+0x1a4/0x328
netlink_sendmsg+0x724/0xa58
The fault is meant to be injected on network interfaces, so skip skbs
that are not associated with a device. Without a device name filter,
such skbs are no longer reallocated either.
Fixes: 12079a59ce52 ("net: Implement fault injection forcing skb reallocation")
Suggested-by: Breno Leitao <leitao@debian.org>
Assisted-by: LLM
Signed-off-by: Haishuang Yan <yanhaishuang@cmss.chinamobile.com>
---
v2:
- Return early for skbs without a device, as suggested by Breno. Such
skbs are now skipped whether or not a device name filter is set.
- Tested on arm64 (QEMU) with KASAN: the netlink broadcast reproducer no
longer oopses with devname set, the devname filter still injects on
the selected device, and without a filter skbs without a device are
skipped while skbs on a device are still reallocated.
v1: https://lore.kernel.org/netdev/20260930122013.110284-1-yanhaishuang@cmss.chinamobile.com/
net/core/skb_fault_injection.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/core/skb_fault_injection.c b/net/core/skb_fault_injection.c
index 4235db6bdfad..63a397f76113 100644
--- a/net/core/skb_fault_injection.c
+++ b/net/core/skb_fault_injection.c
@@ -18,6 +18,9 @@ static bool should_fail_net_realloc_skb(struct sk_buff *skb)
{
struct net_device *net = skb->dev;
+ if (!net)
+ return false;
+
if (skb_realloc.filtered &&
strncmp(net->name, skb_realloc.devname, IFNAMSIZ))
/* device name filter set, but names do not match */
--
2.43.0
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] net: fix NULL dereference in skb realloc fault injection devname filter
2026-10-02 10:30 ` [PATCH net] " Breno Leitao
@ 2026-10-01 18:44 ` Haishuang Yan
0 siblings, 0 replies; 4+ messages in thread
From: Haishuang Yan @ 2026-10-01 18:44 UTC (permalink / raw)
To: Breno Leitao
Cc: netdev, David S . Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Simon Horman, Guillaume Nault, Akinobu Mita,
linux-kernel
On Thu, Oct 01, 2026 at 10:30, Breno Leitao wrote:
> I think something like this untested approach reads better:
>
> + if (!net)
> + return false;
> +
Thanks for the review, Breno. Agreed, this reads better, and the fault
is meant for skbs on a network device anyway.
I sent v2 with your suggestion and added aV Suggested-by tag:
https://lore.kernel.org/netdev/20261001182813.353004-1-yanhaishuang@cmss.chinamobile.com
Thanks,
Haishuang
^ permalink raw reply [flat|nested] 4+ messages in thread
* Re: [PATCH net] net: fix NULL dereference in skb realloc fault injection devname filter
2026-09-30 12:20 [PATCH net] net: fix NULL dereference in skb realloc fault injection devname filter Haishuang Yan
2026-10-01 18:28 ` [PATCH net v2] " Haishuang Yan
@ 2026-10-02 10:30 ` Breno Leitao
2026-10-01 18:44 ` Haishuang Yan
1 sibling, 1 reply; 4+ messages in thread
From: Breno Leitao @ 2026-10-02 10:30 UTC (permalink / raw)
To: Haishuang Yan
Cc: netdev, David S . Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Simon Horman, Guillaume Nault, Akinobu Mita,
linux-kernel
> --- a/net/core/skb_fault_injection.c
> +++ b/net/core/skb_fault_injection.c
> @@ -19,8 +19,8 @@ static bool should_fail_net_realloc_skb(struct sk_buff *skb)
> struct net_device *net = skb->dev;
>
> if (skb_realloc.filtered &&
> - strncmp(net->name, skb_realloc.devname, IFNAMSIZ))
> - /* device name filter set, but names do not match */
> + (!net || strncmp(net->name, skb_realloc.devname, IFNAMSIZ)))
> + /* device name filter set, but no device or names do not match */
> return false;
>
> if (!should_fail(&skb_realloc.attr, 1))
I think something like this untested approach reads better:
diff --git a/net/core/skb_fault_injection.c b/net/core/skb_fault_injection.c
index 4235db6bdfad55..63a397f761133c 100644
--- a/net/core/skb_fault_injection.c
+++ b/net/core/skb_fault_injection.c
@@ -18,6 +18,9 @@ static bool should_fail_net_realloc_skb(struct sk_buff *skb)
{
struct net_device *net = skb->dev;
+ if (!net)
+ return false;
+
if (skb_realloc.filtered &&
strncmp(net->name, skb_realloc.devname, IFNAMSIZ))
/* device name filter set, but names do not match */
^ permalink raw reply [flat|nested] 4+ messages in thread
end of thread, other threads:[~2026-10-02 13:48 UTC | newest]
Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-09-30 12:20 [PATCH net] net: fix NULL dereference in skb realloc fault injection devname filter Haishuang Yan
2026-10-01 18:28 ` [PATCH net v2] " Haishuang Yan
2026-10-02 10:30 ` [PATCH net] " Breno Leitao
2026-10-01 18:44 ` Haishuang Yan
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®