[PATCH net-next 9/9] net: skbuff: don't reset truesize in skb_condense() if the pull fails

From: Josef Bacik

Date: Wed Oct 07 2026 - 14:17:51 EST


skb_condense() pulls all of the frag data into the head and then sets
truesize to cover just the head, but it ignores the return value of
__pskb_pull_tail(). If the pull failed, the frags would still be
attached and truesize would undercount them.

It can't fail today. The caller has checked that the head has room,
that the skb isn't cloned and that the frags are readable, and pulling
all of data_len eats every frag_list skb whole, so nothing is
allocated. Check the result anyway and leave the skb alone on
failure, so this stays correct if any of that changes. Use
__skb_linearize(), which is what this pull is.

Assisted-by: LLM
Signed-off-by: Josef Bacik <josef@xxxxxxxxxxxxxx>
---
net/core/skbuff.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)

diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 43ebe61c7fc4..70df607da05e 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -7118,7 +7118,8 @@ void skb_condense(struct sk_buff *skb)
return;

/* Nice, we can free page frag(s) right now */
- __pskb_pull_tail(skb, skb->data_len);
+ if (__skb_linearize(skb))
+ return;
}
/* At this point, skb->truesize might be over estimated,
* because skb had a fragment, and fragments do not tell

--
2.55.0