Re: [PATCH v2] net: sctp: fix KMSAN uninit-value in sctp_inq_pop
Simon Horman <[email protected]>
| Newsgroups | org.kernel.vger.linux-sctp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev |
|---|---|
| Message-ID | <[email protected]> |
On Fri, Oct 24, 2025 at 05:14:17PM +0530, Ranganath V N wrote: > Fix an issue detected by syzbot: > > KMSAN reported an uninitialized-value access in sctp_inq_pop > BUG: KMSAN: uninit-value in sctp_inq_pop > > The issue is actually caused by skb trimming via sk_filter() in sctp_rcv(). > In the reproducer, skb->len becomes 1 after sk_filter(), which bypassed the > original check: > > if (skb->len < sizeof(struct sctphdr) + sizeof(struct sctp_chunkhdr) + > skb_transport_offset(skb)) > To handle this safely, a new check should be performed after sk_filter(). > > Reported-by: [email protected] > Tested-by: [email protected] > Fixes: https://syzkaller.appspot.com/bug?extid=d101e12bccd4095460e7 Hi, Thanks for your patch. Unfortunately, this is not the correct format for a fixes tag. A fixes tag should reference the commit where the bug was introduced into the tree. In this case, perhaps that is the beginning of git history. If so: Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") I think the URL you provide is appropriate for a Closed tag. Closes: https://syzkaller.appspot.com/bug?extid=d101e12bccd4095460e7 See https://docs.kernel.org/process/submitting-patches.html > Suggested-by: Xin Long <[email protected]> > Signed-off-by: Ranganath V N <[email protected]> > --- > KMSAN reported an uninitialized-value access in sctp_inq_pop > --- > Changes in v2: > - changes in commit message as per the code changes. > - fixed as per the suggestion. > - Link to v1: https://lore.kernel.org/r/[email protected] ...