Re: [PATCH v2] net: sctp: fix KMSAN uninit-value in sctp_inq_pop
Xin Long <[email protected]>
| Newsgroups | org.kernel.vger.linux-sctp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev |
|---|---|
| Message-ID | <CADvbK_dgLr5dUVqc=hxjj3n8wn8azkAp=K2Jr-pcuzUBk+et1Q@mail.gmail.com> |
On Fri, Oct 24, 2025 at 7:44 AM Ranganath V N <[email protected]> wrote: > > Fix an issue detected by syzbot: > > KMSAN reported an uninitialized-value access in sctp_inq_pop > BUG: KMSAN: uninit-value in sctp_inq_pop > > The issue is actually caused by skb trimming via sk_filter() in sctp_rcv(). > In the reproducer, skb->len becomes 1 after sk_filter(), which bypassed the > original check: > > if (skb->len < sizeof(struct sctphdr) + sizeof(struct sctp_chunkhdr) + > skb_transport_offset(skb)) > To handle this safely, a new check should be performed after sk_filter(). > > Reported-by: [email protected] > Tested-by: [email protected] > Fixes: https://syzkaller.appspot.com/bug?extid=d101e12bccd4095460e7 > Suggested-by: Xin Long <[email protected]> > Signed-off-by: Ranganath V N <[email protected]> Acked-by: Xin Long <[email protected]> Thanks for the follow up.