Commit 0c922106 authored by Shaurya Rane's avatar Shaurya Rane Committed by Marc Kleine-Budde
Browse files

net/sched: em_canid: fix uninit-value in em_canid_match



Use pskb_may_pull() to ensure a complete CAN frame is present in the
linear data buffer before reading the CAN ID. A simple skb->len check
is insufficient because it only verifies the total data length but does
not guarantee the data is present in skb->data (it could be in
fragments).

pskb_may_pull() both validates the length and pulls fragmented data
into the linear buffer if necessary, making it safe to directly
access skb->data.

Reported-by: default avatar <syzbot+5d8269a1e099279152bc@syzkaller.appspotmail.com>
Closes: https://syzkaller.appspot.com/bug?extid=5d8269a1e099279152bc


Fixes: f057bbb6 ("net: em_canid: Ematch rule to match CAN frames according to their identifiers")
Signed-off-by: default avatarShaurya Rane <ssrane_b23@ee.vjti.ac.in>
Link: https://patch.msgid.link/20251126085718.50808-1-ssranevjti@gmail.com


Signed-off-by: default avatarMarc Kleine-Budde <mkl@pengutronix.de>
parent 6d849ff5
Loading
Loading
Loading
Loading
+3 −0
Original line number Diff line number Diff line
@@ -99,6 +99,9 @@ static int em_canid_match(struct sk_buff *skb, struct tcf_ematch *m,
	int i;
	const struct can_filter *lp;

	if (!pskb_may_pull(skb, CAN_MTU))
		return 0;

	can_id = em_canid_get_id(skb);

	if (can_id & CAN_EFF_FLAG) {