Re: [syzbot] [batman?] KMSAN: uninit-value in skb_clone
From: shaurya
Date: Tue Nov 25 2025 - 15:04:05 EST
#syz test:
git://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git master
From ff66dd840d93efe5914a824b0d4d58031115d788 Mon Sep 17 00:00:00 2001
From: Shaurya Rane <ssrane_b23@xxxxxxxxxxxxx>
Date: Wed, 26 Nov 2025 01:25:03 +0530
Subject: [PATCH] hsr: fix NULL pointer dereference in skb_clone with hw tag
insertion
When hardware HSR tag insertion is enabled (NETIF_F_HW_HSR_TAG_INS) and
frame->skb_std is NULL, both hsr_create_tagged_frame() and
prp_create_tagged_frame() will call skb_clone() with a NULL skb pointer,
causing a kernel crash.
Fix this by adding NULL checks for frame->skb_std before calling
skb_clone() in the functions.
Reported-by: syzbot+2fa344348a579b779e05@xxxxxxxxxxxxxxxxxxxxxxxxx
Fixes: f266a683a480 (\"net/hsr: Better frame dispatch\")
Signed-off-by: Shaurya Rane <ssrane_b23@xxxxxxxxxxxxx>
---
net/hsr/hsr_forward.c | 7 +++++++
1 file changed, 7 insertions(+)
diff --git a/net/hsr/hsr_forward.c b/net/hsr/hsr_forward.c
index 339f0d220212..4c1a311b900f 100644
--- a/net/hsr/hsr_forward.c
+++ b/net/hsr/hsr_forward.c
@@ -211,6 +211,9 @@ struct sk_buff *prp_get_untagged_frame(struct hsr_frame_info *frame,
__FILE__, __LINE__, port->dev->name);
return NULL;
}
+
+ if (!frame->skb_std)
+ return NULL;
}
return skb_clone(frame->skb_std, GFP_ATOMIC);
@@ -341,6 +344,8 @@ struct sk_buff *hsr_create_tagged_frame(struct hsr_frame_info *frame,
hsr_set_path_id(frame, hsr_ethhdr, port);
return skb_clone(frame->skb_hsr, GFP_ATOMIC);
} else if (port->dev->features & NETIF_F_HW_HSR_TAG_INS) {
+ if (!frame->skb_std)
+ return NULL;
return skb_clone(frame->skb_std, GFP_ATOMIC);
}
@@ -385,6 +390,8 @@ struct sk_buff *prp_create_tagged_frame(struct hsr_frame_info *frame,
}
return skb_clone(frame->skb_prp, GFP_ATOMIC);
} else if (port->dev->features & NETIF_F_HW_HSR_TAG_INS) {
+ if (!frame->skb_std)
+ return NULL;
return skb_clone(frame->skb_std, GFP_ATOMIC);
}
--
2.34.1