[PATCH] net: datagram: fix integer overflow in zerocopy_sg_from_iter
From: Jiangshan Yi
Date: Tue Jul 28 2026 - 02:49:56 EST
zerocopy_sg_from_iter() computes the copy length as:
copy = min_t(int, skb_headlen(skb), iov_iter_count(from));
iov_iter_count() returns size_t. When it exceeds INT_MAX (e.g. via
io_uring provided buffers), the int cast wraps negative, wins the min()
comparison, and the negative copy propagates into
skb_copy_datagram_from_iter(), which can trigger WARN_ON or corrupt
data.
Use min_t(size_t, ...) so the comparison is done in the correct type.
The result is always <= skb_headlen(skb), which fits in int.
Fixes: 3a654f975bf9 ("new helpers: skb_copy_datagram_from_iter() and zerocopy_sg_from_iter()")
Cc: stable@xxxxxxxxxxxxxxx
Signed-off-by: Jiangshan Yi <yijiangshan@xxxxxxxxxx>
---
net/core/datagram.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
diff --git a/net/core/datagram.c b/net/core/datagram.c
index c285c6465923..fd8e17d25a3d 100644
--- a/net/core/datagram.c
+++ b/net/core/datagram.c
@@ -783,7 +783,7 @@ EXPORT_SYMBOL(__zerocopy_sg_from_iter);
*/
int zerocopy_sg_from_iter(struct sk_buff *skb, struct iov_iter *from)
{
- int copy = min_t(int, skb_headlen(skb), iov_iter_count(from));
+ int copy = min_t(size_t, skb_headlen(skb), iov_iter_count(from));
/* copy up to skb headlen */
if (skb_copy_datagram_from_iter(skb, 0, from, copy))
--
2.25.1