[PATCH] net: datagram: fix integer overflow in zerocopy_sg_from_iter

From: Jiangshan Yi

Date: Tue Jul 28 2026 - 02:49:56 EST


zerocopy_sg_from_iter() computes the copy length as:

copy = min_t(int, skb_headlen(skb), iov_iter_count(from));

iov_iter_count() returns size_t. When it exceeds INT_MAX (e.g. via
io_uring provided buffers), the int cast wraps negative, wins the min()
comparison, and the negative copy propagates into
skb_copy_datagram_from_iter(), which can trigger WARN_ON or corrupt
data.

Use min_t(size_t, ...) so the comparison is done in the correct type.
The result is always <= skb_headlen(skb), which fits in int.

Fixes: 3a654f975bf9 ("new helpers: skb_copy_datagram_from_iter() and zerocopy_sg_from_iter()")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Jiangshan Yi <yijiangshan@xxxxxxxxxx>
---
net/core/datagram.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/net/core/datagram.c b/net/core/datagram.c
index c285c6465923..fd8e17d25a3d 100644
--- a/net/core/datagram.c
+++ b/net/core/datagram.c
@@ -783,7 +783,7 @@ EXPORT_SYMBOL(__zerocopy_sg_from_iter);
*/
int zerocopy_sg_from_iter(struct sk_buff *skb, struct iov_iter *from)
{
- int copy = min_t(int, skb_headlen(skb), iov_iter_count(from));
+ int copy = min_t(size_t, skb_headlen(skb), iov_iter_count(from));

/* copy up to skb headlen */
if (skb_copy_datagram_from_iter(skb, 0, from, copy))
--
2.25.1