Re: [PATCH net v3] net: fix NULL dereference in skb realloc fault injection devname filter
From: Breno Leitao
Date: Wed Oct 07 2026 - 05:10:13 EST
On Wed, Oct 07, 2026 at 08:41:58AM +0800, Haishuang Yan wrote:
> When a device name filter is set in
> /sys/kernel/debug/fail_skb_realloc/devname, should_fail_net_realloc_skb()
> compares it with skb->dev->name without checking skb->dev first.
>
> skb_might_realloc() is called from pskb_may_pull(), pskb_trim() and
> pskb_trim_rcsum(), which also run on skbs that are not associated with
> a device. One example is a netlink broadcast to a listener with a socket
> filter attached, which goes through sk_filter_trim_cap(). With the
> filter set, such an skb makes the kernel oops:
>
> KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]
> pc : strncmp+0x50/0xf0
> lr : skb_might_realloc+0x58/0xa0
> Call trace:
> strncmp+0x50/0xf0 (P)
> skb_might_realloc+0x58/0xa0
> sk_filter_trim_cap+0x6a0/0x928
> do_one_broadcast+0x35c/0xb20
> netlink_broadcast_filtered+0x1a4/0x328
> netlink_sendmsg+0x724/0xa58
>
> The fault is meant to be injected on network interfaces, so skip skbs
> that are not associated with a device. Without a device name filter,
> such skbs are no longer reallocated either.
>
> Fixes: 12079a59ce52 ("net: Implement fault injection forcing skb reallocation")
> Suggested-by: Breno Leitao <leitao@xxxxxxxxxx>
> Assisted-by: LLM
> Signed-off-by: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
Reviewed-by: Breno Leitao <leitao@xxxxxxxxxx>