[PATCH v3 3/3] can: dev: can_put_echo_skb(): free skb on invalid echo index

From: Cunhao Lu

Date: Fri Jul 31 2026 - 05:47:16 EST


can_put_echo_skb() consumes the skb on all paths except when the echo
index is out of bounds. This leaves ownership with the caller on -EINVAL,
unlike the other error paths, and can leak the skb if the caller expects
consistent semantics.

Free the skb before returning -EINVAL so that all return paths consume it.

Fixes: 6411959c10fe ("can: dev: can_put_echo_skb(): don't crash kernel if can_priv::echo_skb is accessed out of bounds")
Cc: stable@xxxxxxxxxxxxxxx
Reviewed-by: Vincent Mailhol <mailhol@xxxxxxxxxx>
Signed-off-by: Cunhao Lu <1579567540@xxxxxx>
---
Changes in v2:
- Free the skb with dev_kfree_skb_any() on an invalid echo index.
- Collect Vincent's Reviewed-by tag
---
drivers/net/can/dev/skb.c | 1 +
1 file changed, 1 insertion(+)

diff --git a/drivers/net/can/dev/skb.c b/drivers/net/can/dev/skb.c
index d34d3e7d4c9f..e985616c062c 100644
--- a/drivers/net/can/dev/skb.c
+++ b/drivers/net/can/dev/skb.c
@@ -54,6 +54,7 @@ int can_put_echo_skb(struct sk_buff *skb, struct net_device *dev,
if (idx >= priv->echo_skb_max) {
netdev_err(dev, "%s: BUG! Trying to access can_priv::echo_skb out of bounds (%u/max %u)\n",
__func__, idx, priv->echo_skb_max);
+ dev_kfree_skb_any(skb);
return -EINVAL;
}


--
2.34.1