Re: [PATCH net] net: fix NULL dereference in skb realloc fault injection devname filter
From: Breno Leitao
Date: Fri Oct 02 2026 - 06:49:32 EST
> --- a/net/core/skb_fault_injection.c
> +++ b/net/core/skb_fault_injection.c
> @@ -19,8 +19,8 @@ static bool should_fail_net_realloc_skb(struct sk_buff *skb)
> struct net_device *net = skb->dev;
>
> if (skb_realloc.filtered &&
> - strncmp(net->name, skb_realloc.devname, IFNAMSIZ))
> - /* device name filter set, but names do not match */
> + (!net || strncmp(net->name, skb_realloc.devname, IFNAMSIZ)))
> + /* device name filter set, but no device or names do not match */
> return false;
>
> if (!should_fail(&skb_realloc.attr, 1))
I think something like this untested approach reads better:
diff --git a/net/core/skb_fault_injection.c b/net/core/skb_fault_injection.c
index 4235db6bdfad55..63a397f761133c 100644
--- a/net/core/skb_fault_injection.c
+++ b/net/core/skb_fault_injection.c
@@ -18,6 +18,9 @@ static bool should_fail_net_realloc_skb(struct sk_buff *skb)
{
struct net_device *net = skb->dev;
+ if (!net)
+ return false;
+
if (skb_realloc.filtered &&
strncmp(net->name, skb_realloc.devname, IFNAMSIZ))
/* device name filter set, but names do not match */