[PATCH net v2] net: fix NULL dereference in skb realloc fault injection devname filter

From: Haishuang Yan

Date: Fri Oct 02 2026 - 09:34:17 EST


When a device name filter is set in
/sys/kernel/debug/fail_skb_realloc/devname, should_fail_net_realloc_skb()
compares it with skb->dev->name without checking skb->dev first.

skb_might_realloc() is called from pskb_may_pull(), __skb_cow() and
pskb_trim(), which also run on skbs that are not associated with a
device. One example is a netlink broadcast to a listener with a socket
filter attached, which goes through sk_filter_trim_cap(). With the
filter set, such an skb makes the kernel oops:

KASAN: null-ptr-deref in range [0x0000000000000118-0x000000000000011f]
pc : strncmp+0x50/0xf0
lr : skb_might_realloc+0x58/0xa0
Call trace:
strncmp+0x50/0xf0 (P)
skb_might_realloc+0x58/0xa0
sk_filter_trim_cap+0x6a0/0x928
do_one_broadcast+0x35c/0xb20
netlink_broadcast_filtered+0x1a4/0x328
netlink_sendmsg+0x724/0xa58

The fault is meant to be injected on network interfaces, so skip skbs
that are not associated with a device. Without a device name filter,
such skbs are no longer reallocated either.

Fixes: 12079a59ce52 ("net: Implement fault injection forcing skb reallocation")
Suggested-by: Breno Leitao <leitao@xxxxxxxxxx>
Assisted-by: LLM
Signed-off-by: Haishuang Yan <yanhaishuang@xxxxxxxxxxxxxxxxxxxx>
---
v2:
- Return early for skbs without a device, as suggested by Breno. Such
skbs are now skipped whether or not a device name filter is set.
- Tested on arm64 (QEMU) with KASAN: the netlink broadcast reproducer no
longer oopses with devname set, the devname filter still injects on
the selected device, and without a filter skbs without a device are
skipped while skbs on a device are still reallocated.

v1: https://lore.kernel.org/netdev/20260930122013.110284-1-yanhaishuang@xxxxxxxxxxxxxxxxxxxx/

net/core/skb_fault_injection.c | 3 +++
1 file changed, 3 insertions(+)

diff --git a/net/core/skb_fault_injection.c b/net/core/skb_fault_injection.c
index 4235db6bdfad..63a397f76113 100644
--- a/net/core/skb_fault_injection.c
+++ b/net/core/skb_fault_injection.c
@@ -18,6 +18,9 @@ static bool should_fail_net_realloc_skb(struct sk_buff *skb)
{
struct net_device *net = skb->dev;

+ if (!net)
+ return false;
+
if (skb_realloc.filtered &&
strncmp(net->name, skb_realloc.devname, IFNAMSIZ))
/* device name filter set, but names do not match */
--
2.43.0