mirror of https://lore.kernel.org/lkml/
 help / color / mirror / Atom feed
* [PATCH net v3] net: fix NULL dereference in skb realloc fault injection devname filter
@ 2026-10-07  0:41 Haishuang Yan
  2026-10-07  9:01 ` Breno Leitao
  0 siblings, 1 reply; 2+ messages in thread
From: Haishuang Yan @ 2026-10-07  0:41 UTC (permalink / raw)
  To: netdev
  Cc: Breno Leitao, David S . Miller, Eric Dumazet, Jakub Kicinski,
	Paolo Abeni, Simon Horman, Guillaume Nault, Akinobu Mita,
	linux-kernel, Haishuang Yan

When a device name filter is set in
/sys/kernel/debug/fail_skb_realloc/devname, should_fail_net_realloc_skb()
compares it with skb->dev->name without checking skb->dev first.

skb_might_realloc() is called from pskb_may_pull(), pskb_trim() and
pskb_trim_rcsum(), which also run on skbs that are not associated with
a device. One example is a netlink broadcast to a listener with a socket
filter attached, which goes through sk_filter_trim_cap(). With the
filter set, such an skb makes the kernel oops:

  KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]
  pc : strncmp+0x50/0xf0
  lr : skb_might_realloc+0x58/0xa0
  Call trace:
   strncmp+0x50/0xf0 (P)
   skb_might_realloc+0x58/0xa0
   sk_filter_trim_cap+0x6a0/0x928
   do_one_broadcast+0x35c/0xb20
   netlink_broadcast_filtered+0x1a4/0x328
   netlink_sendmsg+0x724/0xa58

The fault is meant to be injected on network interfaces, so skip skbs
that are not associated with a device. Without a device name filter,
such skbs are no longer reallocated either.

Fixes: 12079a59ce52 ("net: Implement fault injection forcing skb reallocation")
Suggested-by: Breno Leitao <leitao@debian.org>
Assisted-by: LLM
Signed-off-by: Haishuang Yan <yanhaishuang@cmss.chinamobile.com>
---
v3:
- Fix the list of functions that call skb_might_realloc() in the commit
  message (Sashiko). No code change.
- Post as a new thread, v2 was sent as a reply to v1 by mistake.
v2: https://lore.kernel.org/netdev/20261001182813.353004-1-yanhaishuang@cmss.chinamobile.com/
- Return early for skbs without a device, as suggested by Breno. Such
  skbs are now skipped whether or not a device name filter is set.
- Tested on arm64 (QEMU) with KASAN: the netlink broadcast reproducer no
  longer oopses with devname set, the devname filter still injects on
  the selected device, and without a filter skbs without a device are
  skipped while skbs on a device are still reallocated.
v1: https://lore.kernel.org/netdev/20260930122013.110284-1-yanhaishuang@cmss.chinamobile.com/

 net/core/skb_fault_injection.c | 3 +++
 1 file changed, 3 insertions(+)

diff --git a/net/core/skb_fault_injection.c b/net/core/skb_fault_injection.c
index 4235db6bdfad..63a397f76113 100644
--- a/net/core/skb_fault_injection.c
+++ b/net/core/skb_fault_injection.c
@@ -18,6 +18,9 @@ static bool should_fail_net_realloc_skb(struct sk_buff *skb)
 {
 	struct net_device *net = skb->dev;
 
+	if (!net)
+		return false;
+
 	if (skb_realloc.filtered &&
 	    strncmp(net->name, skb_realloc.devname, IFNAMSIZ))
 		/* device name filter set, but names do not match */
-- 
2.43.0




^ permalink raw reply	[flat|nested] 2+ messages in thread

* Re: [PATCH net v3] net: fix NULL dereference in skb realloc fault injection devname filter
  2026-10-07  0:41 [PATCH net v3] net: fix NULL dereference in skb realloc fault injection devname filter Haishuang Yan
@ 2026-10-07  9:01 ` Breno Leitao
  0 siblings, 0 replies; 2+ messages in thread
From: Breno Leitao @ 2026-10-07  9:01 UTC (permalink / raw)
  To: Haishuang Yan
  Cc: netdev, David S . Miller, Eric Dumazet, Jakub Kicinski,
	Paolo Abeni, Simon Horman, Guillaume Nault, Akinobu Mita,
	linux-kernel

On Wed, Oct 07, 2026 at 08:41:58AM +0800, Haishuang Yan wrote:
> When a device name filter is set in
> /sys/kernel/debug/fail_skb_realloc/devname, should_fail_net_realloc_skb()
> compares it with skb->dev->name without checking skb->dev first.
> 
> skb_might_realloc() is called from pskb_may_pull(), pskb_trim() and
> pskb_trim_rcsum(), which also run on skbs that are not associated with
> a device. One example is a netlink broadcast to a listener with a socket
> filter attached, which goes through sk_filter_trim_cap(). With the
> filter set, such an skb makes the kernel oops:
> 
>   KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]
>   pc : strncmp+0x50/0xf0
>   lr : skb_might_realloc+0x58/0xa0
>   Call trace:
>    strncmp+0x50/0xf0 (P)
>    skb_might_realloc+0x58/0xa0
>    sk_filter_trim_cap+0x6a0/0x928
>    do_one_broadcast+0x35c/0xb20
>    netlink_broadcast_filtered+0x1a4/0x328
>    netlink_sendmsg+0x724/0xa58
> 
> The fault is meant to be injected on network interfaces, so skip skbs
> that are not associated with a device. Without a device name filter,
> such skbs are no longer reallocated either.
> 
> Fixes: 12079a59ce52 ("net: Implement fault injection forcing skb reallocation")
> Suggested-by: Breno Leitao <leitao@debian.org>
> Assisted-by: LLM
> Signed-off-by: Haishuang Yan <yanhaishuang@cmss.chinamobile.com>

Reviewed-by: Breno Leitao <leitao@debian.org>

^ permalink raw reply	[flat|nested] 2+ messages in thread

end of thread, other threads:[~2026-10-07  9:01 UTC | newest]

Thread overview: 2+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2026-10-07  0:41 [PATCH net v3] net: fix NULL dereference in skb realloc fault injection devname filter Haishuang Yan
2026-10-07  9:01 ` Breno Leitao

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox

all inboxes | Powered by JetHome®