[PATCH net-next v2 1/8] net: skbuff: don't BUG() on bad arguments to pskb_expand_head()
From: Josef Bacik
Date: Wed Oct 07 2026 - 13:37:23 EST
pskb_expand_head() BUG()s if it is handed a negative nhead or a shared
skb. Both are bugs in the caller, and both keep getting hit: commit
2cbb259ec4f8 ("bpf: Reject negative head_room in __bpf_skb_change_head")
and commit 64e6a754d33d ("llc: do not use skb_get() before
dev_queue_xmit()") each fixed a crash here that took down the whole box.
The function already returns an error that every caller has to handle,
and at this point it hasn't touched the skb. Return -EINVAL instead of
crashing. The warning is DEBUG_NET_WARN_ON_ONCE(), so debug kernels
still point at the caller, while production kernels, including ones
running with panic_on_warn, just fail the call.
Assisted-by: LLM
Signed-off-by: Josef Bacik <josef@xxxxxxxxxxxxxx>
---
net/core/skbuff.c | 10 ++++++++--
1 file changed, 8 insertions(+), 2 deletions(-)
diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 43ebe61c7fc4..d226fe77d484 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -2303,9 +2303,15 @@ int pskb_expand_head(struct sk_buff *skb, int nhead, int ntail,
u8 *data;
int i;
- BUG_ON(nhead < 0);
+ if (unlikely(nhead < 0)) {
+ DEBUG_NET_WARN_ON_ONCE(1);
+ return -EINVAL;
+ }
- BUG_ON(skb_shared(skb));
+ if (unlikely(skb_shared(skb))) {
+ DEBUG_NET_WARN_ON_ONCE(1);
+ return -EINVAL;
+ }
skb_zcopy_downgrade_managed(skb);
--
2.55.0