Re: [PATCH v3] net: sctp: fix KMSAN uninit-value in sctp_inq_pop
Simon Horman <[email protected]>
| Newsgroups | org.kernel.vger.linux-sctp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev |
|---|---|
| Message-ID | <[email protected]> |
On Sun, Oct 26, 2025 at 10:03:12PM +0530, Ranganath V N wrote: > Fix an issue detected by syzbot: > > KMSAN reported an uninitialized-value access in sctp_inq_pop > BUG: KMSAN: uninit-value in sctp_inq_pop > > The issue is actually caused by skb trimming via sk_filter() in sctp_rcv(). > In the reproducer, skb->len becomes 1 after sk_filter(), which bypassed the > original check: > > if (skb->len < sizeof(struct sctphdr) + sizeof(struct sctp_chunkhdr) + > skb_transport_offset(skb)) > To handle this safely, a new check should be performed after sk_filter(). > > Reported-by: [email protected] > Tested-by: [email protected] > Closes: https://syzkaller.appspot.com/bug?extid=d101e12bccd4095460e7 > Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2") > Suggested-by: Xin Long <[email protected]> > Signed-off-by: Ranganath V N <[email protected]> > --- > KMSAN reported an uninitialized-value access in sctp_inq_pop > --- > Changes in v3: > - fixes the patch format like fixes and closes tags. > - Link to v2: https://lore.kernel.org/r/[email protected] Thanks for the update. This version looks good to me. And I assume it is for net. Reviewed-by: Simon Horman <[email protected]>