* [PATCH net v3] net: fix NULL dereference in skb realloc fault injection devname filter
@ 2026-10-07 0:41 Haishuang Yan
2026-10-07 9:01 ` Breno Leitao
0 siblings, 1 reply; 2+ messages in thread
From: Haishuang Yan @ 2026-10-07 0:41 UTC (permalink / raw)
To: netdev
Cc: Breno Leitao, David S . Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Simon Horman, Guillaume Nault, Akinobu Mita,
linux-kernel, Haishuang Yan
When a device name filter is set in
/sys/kernel/debug/fail_skb_realloc/devname, should_fail_net_realloc_skb()
compares it with skb->dev->name without checking skb->dev first.
skb_might_realloc() is called from pskb_may_pull(), pskb_trim() and
pskb_trim_rcsum(), which also run on skbs that are not associated with
a device. One example is a netlink broadcast to a listener with a socket
filter attached, which goes through sk_filter_trim_cap(). With the
filter set, such an skb makes the kernel oops:
KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]
pc : strncmp+0x50/0xf0
lr : skb_might_realloc+0x58/0xa0
Call trace:
strncmp+0x50/0xf0 (P)
skb_might_realloc+0x58/0xa0
sk_filter_trim_cap+0x6a0/0x928
do_one_broadcast+0x35c/0xb20
netlink_broadcast_filtered+0x1a4/0x328
netlink_sendmsg+0x724/0xa58
The fault is meant to be injected on network interfaces, so skip skbs
that are not associated with a device. Without a device name filter,
such skbs are no longer reallocated either.
Fixes: 12079a59ce52 ("net: Implement fault injection forcing skb reallocation")
Suggested-by: Breno Leitao <leitao@debian.org>
Assisted-by: LLM
Signed-off-by: Haishuang Yan <yanhaishuang@cmss.chinamobile.com>
---
v3:
- Fix the list of functions that call skb_might_realloc() in the commit
message (Sashiko). No code change.
- Post as a new thread, v2 was sent as a reply to v1 by mistake.
v2: https://lore.kernel.org/netdev/20261001182813.353004-1-yanhaishuang@cmss.chinamobile.com/
- Return early for skbs without a device, as suggested by Breno. Such
skbs are now skipped whether or not a device name filter is set.
- Tested on arm64 (QEMU) with KASAN: the netlink broadcast reproducer no
longer oopses with devname set, the devname filter still injects on
the selected device, and without a filter skbs without a device are
skipped while skbs on a device are still reallocated.
v1: https://lore.kernel.org/netdev/20260930122013.110284-1-yanhaishuang@cmss.chinamobile.com/
net/core/skb_fault_injection.c | 3 +++
1 file changed, 3 insertions(+)
diff --git a/net/core/skb_fault_injection.c b/net/core/skb_fault_injection.c
index 4235db6bdfad..63a397f76113 100644
--- a/net/core/skb_fault_injection.c
+++ b/net/core/skb_fault_injection.c
@@ -18,6 +18,9 @@ static bool should_fail_net_realloc_skb(struct sk_buff *skb)
{
struct net_device *net = skb->dev;
+ if (!net)
+ return false;
+
if (skb_realloc.filtered &&
strncmp(net->name, skb_realloc.devname, IFNAMSIZ))
/* device name filter set, but names do not match */
--
2.43.0
^ permalink raw reply [flat|nested] 2+ messages in thread
* Re: [PATCH net v3] net: fix NULL dereference in skb realloc fault injection devname filter
2026-10-07 0:41 [PATCH net v3] net: fix NULL dereference in skb realloc fault injection devname filter Haishuang Yan
@ 2026-10-07 9:01 ` Breno Leitao
0 siblings, 0 replies; 2+ messages in thread
From: Breno Leitao @ 2026-10-07 9:01 UTC (permalink / raw)
To: Haishuang Yan
Cc: netdev, David S . Miller, Eric Dumazet, Jakub Kicinski,
Paolo Abeni, Simon Horman, Guillaume Nault, Akinobu Mita,
linux-kernel
On Wed, Oct 07, 2026 at 08:41:58AM +0800, Haishuang Yan wrote:
> When a device name filter is set in
> /sys/kernel/debug/fail_skb_realloc/devname, should_fail_net_realloc_skb()
> compares it with skb->dev->name without checking skb->dev first.
>
> skb_might_realloc() is called from pskb_may_pull(), pskb_trim() and
> pskb_trim_rcsum(), which also run on skbs that are not associated with
> a device. One example is a netlink broadcast to a listener with a socket
> filter attached, which goes through sk_filter_trim_cap(). With the
> filter set, such an skb makes the kernel oops:
>
> KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]
> pc : strncmp+0x50/0xf0
> lr : skb_might_realloc+0x58/0xa0
> Call trace:
> strncmp+0x50/0xf0 (P)
> skb_might_realloc+0x58/0xa0
> sk_filter_trim_cap+0x6a0/0x928
> do_one_broadcast+0x35c/0xb20
> netlink_broadcast_filtered+0x1a4/0x328
> netlink_sendmsg+0x724/0xa58
>
> The fault is meant to be injected on network interfaces, so skip skbs
> that are not associated with a device. Without a device name filter,
> such skbs are no longer reallocated either.
>
> Fixes: 12079a59ce52 ("net: Implement fault injection forcing skb reallocation")
> Suggested-by: Breno Leitao <leitao@debian.org>
> Assisted-by: LLM
> Signed-off-by: Haishuang Yan <yanhaishuang@cmss.chinamobile.com>
Reviewed-by: Breno Leitao <leitao@debian.org>
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2026-10-07 9:01 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-07 0:41 [PATCH net v3] net: fix NULL dereference in skb realloc fault injection devname filter Haishuang Yan
2026-10-07 9:01 ` Breno Leitao
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox
all inboxes | Powered by JetHome®