[PATCH net-next v2 7/8] net: skbuff: don't BUG() on a missing head_frag in skb_zerocopy()

From: Josef Bacik

Date: Wed Oct 07 2026 - 13:39:34 EST


skb_zerocopy() BUG()s if @from has no head_frag and the caller passed
hlen == 0, meaning the caller didn't ask for the head to be copied and
the head can't be referenced as a page either. The check runs before
anything is touched, and skb_zerocopy() already documents -EFAULT for
bad skb geometry. Return that, with a DEBUG_NET_WARN_ON_ONCE() for
debug kernels.

Assisted-by: LLM
Signed-off-by: Josef Bacik <josef@xxxxxxxxxxxxxx>
---
net/core/skbuff.c | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)

diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 7fd2f8142cc4..629de22d98e4 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -3913,7 +3913,10 @@ skb_zerocopy(struct sk_buff *to, struct sk_buff *from, int len, int hlen)
struct page *page;
unsigned int offset;

- BUG_ON(!from->head_frag && !hlen);
+ if (unlikely(!from->head_frag && !hlen)) {
+ DEBUG_NET_WARN_ON_ONCE(1);
+ return -EFAULT;
+ }

/* dont bother with small payloads */
if (len <= skb_tailroom(to))

--
2.55.0