[PATCH net] net: fix NULL dereference in skb realloc fault injection devname filter
From: Haishuang Yan
Date: Wed Sep 30 2026 - 12:46:26 EST
When a device name filter is set in
/sys/kernel/debug/fail_skb_realloc/devname, should_fail_net_realloc_skb()
compares it with skb->dev->name without checking skb->dev first.
skb_might_realloc() is called from pskb_may_pull(), __skb_cow() and
pskb_trim(), which also run on skbs that are not associated with a
device. One example is a netlink broadcast to a listener with a socket
filter attached, which goes through sk_filter_trim_cap(). With the
filter set, such an skb makes the kernel oops:
KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]
pc : strncmp+0x50/0xf0
lr : skb_might_realloc+0x58/0xa0
Call trace:
strncmp+0x50/0xf0 (P)
skb_might_realloc+0x58/0xa0
sk_filter_trim_cap+0x6a0/0x928
do_one_broadcast+0x35c/0xb20
netlink_broadcast_filtered+0x1a4/0x328
netlink_sendmsg+0x724/0xa58
An skb without a device cannot match the configured device name, so do
not inject a reallocation for it.
Fixes: 12079a59ce52 ("net: Implement fault injection forcing skb reallocation")
Assisted-by: LLM
Signed-off-by: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
---
net/core/skb_fault_injection.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
diff --git a/net/core/skb_fault_injection.c b/net/core/skb_fault_injection.c
index 4235db6bdfad..7f8315c864c8 100644
--- a/net/core/skb_fault_injection.c
+++ b/net/core/skb_fault_injection.c
@@ -19,8 +19,8 @@ static bool should_fail_net_realloc_skb(struct sk_buff *skb)
struct net_device *net = skb->dev;
if (skb_realloc.filtered &&
- strncmp(net->name, skb_realloc.devname, IFNAMSIZ))
- /* device name filter set, but names do not match */
+ (!net || strncmp(net->name, skb_realloc.devname, IFNAMSIZ)))
+ /* device name filter set, but no device or names do not match */
return false;
if (!should_fail(&skb_realloc.attr, 1))
--
2.43.0