Re: [BUG] WARNING in lowpan_compress_addr_64
From: Farhad Alemi
Date: Mon Sep 07 2026 - 21:33:47 EST
The patched kernel (this patch on 28924df2a08f) does not panic on the
attached reproducer.
Tested-by: Farhad Alemi <farhad.alemi@xxxxxxxxxxxx>
On Fri, Aug 28, 2026 at 12:46 AM Eric Dumazet <edumazet@xxxxxxxxxx> wrote:
>
> On Fri, Aug 28, 2026 at 9:22 AM Farhad Alemi <farhad.alemi@xxxxxxxxxxxx> wrote:
> >
> > Hello,
> >
> > As part of the kernel research at ASU's SEFCOM
> > lab, we hit the crash below. Crash reports can be found here:
> >
> > https://github.com/farhad-alemi/public_bug_reports/tree/main/182-warning-in-lowpan-compress-addr-64/
> >
> > WARNING: net/6lowpan/iphc.c:937 at
> > lowpan_iphc_compress_802154_lladdr net/6lowpan/iphc.c:937 [inline],
> > CPU#0: syz.9.76/13660
> > WARNING: net/6lowpan/iphc.c:937 at
> > lowpan_compress_addr_64+0x4be/0x9c0 net/6lowpan/iphc.c:952, CPU#0:
> > syz.9.76/13660
> > RIP: 0010:lowpan_compress_addr_64+0x4be/0x9c0 net/6lowpan/iphc.c:952
> > Call Trace:
> > lowpan_compress_addr_64+0x4be/0x9c0 net/6lowpan/iphc.c:952
> > lowpan_header_compress+0xeef/0x1ef0 net/6lowpan/iphc.c:1242
> > lowpan_header net/ieee802154/6lowpan/tx.c:234 [inline]
> > lowpan_xmit+0x4c6/0x1420 net/ieee802154/6lowpan/tx.c:282
> > dev_hard_start_xmit+0x23b/0x620 net/core/dev.c:3904
> > __dev_queue_xmit+0x11e7/0x3250 net/core/dev.c:4870
> > packet_snd net/packet/af_packet.c:3082 [inline]
> > packet_sendmsg+0x3d9b/0x5150 net/packet/af_packet.c:3114
> > Kernel panic - not syncing: kernel: panic_on_warn set ...
> >
> > Our reproducer.c is available upon request.
> >
> > Happy to test a patch if that would help.
>
> Thanks for the report.
>
> All these WARN_ON_ONCE() are bogus in modern days (panic_on_warn being
> used by fuzzers)
> Developers probably used them to catch unexpected packets.
> Guess what, fuzzers do exactly that.
>
> Also lowpan_header_create() seems to incorrectly return 0 instead of an error.
>
> Can you try:
>
> diff --git a/net/6lowpan/iphc.c b/net/6lowpan/iphc.c
> index 37eaff3f7b6940b73924c38c360adf482d6cceab..dec04f63f1b2599a7291d020e662f4d129333c14
> 100644
> --- a/net/6lowpan/iphc.c
> +++ b/net/6lowpan/iphc.c
> @@ -180,8 +180,6 @@ lowpan_iphc_uncompress_802154_lladdr(struct
> in6_addr *ipaddr,
> &addr->short_addr);
> break;
> default:
> - /* should never handled and filtered by 802154 6lowpan */
> - WARN_ON_ONCE(1);
> break;
> }
> }
> @@ -820,8 +818,6 @@ lowpan_iphc_compress_ctx_802154_lladdr(const
> struct in6_addr *ipaddr,
> lladdr_compress = true;
> break;
> default:
> - /* should never handled and filtered by 802154 6lowpan */
> - WARN_ON_ONCE(1);
> break;
> }
>
> @@ -933,8 +929,6 @@ lowpan_iphc_compress_802154_lladdr(const struct
> in6_addr *ipaddr,
> lladdr_compress = true;
> break;
> default:
> - /* should never handled and filtered by 802154 6lowpan */
> - WARN_ON_ONCE(1);
> break;
> }
>
> diff --git a/net/ieee802154/6lowpan/tx.c b/net/ieee802154/6lowpan/tx.c
> index 4df76ff50699ede5c187c9cca6f0cc10b19d2123..9bffe01cc448fcb993883748f359cc71b879a729
> 100644
> --- a/net/ieee802154/6lowpan/tx.c
> +++ b/net/ieee802154/6lowpan/tx.c
> @@ -47,7 +47,7 @@ int lowpan_header_create(struct sk_buff *skb, struct
> net_device *ldev,
> * if this package isn't ipv6 one, where should it be routed?
> */
> if (type != ETH_P_IPV6)
> - return 0;
> + return -EINVAL;
>
> /* intra-pan communication */
> info->saddr.pan_id = wpan_dev->pan_id;
Attachment:
reproducer.c
Description: Binary data