Commit 35eaa6d8 authored by Nikola Z. Ivanov's avatar Nikola Z. Ivanov Committed by Jakub Kicinski
Browse files

netdevsim: zero initialize struct iphdr in dummy sk_buff

Syzbot reports a KMSAN uninit-value originating from
nsim_dev_trap_skb_build, with the allocation also
being performed in the same function.

Fix this by calling skb_put_zero instead of skb_put to
guarantee zero initialization of the whole IP header.

Closes: https://syzkaller.appspot.com/bug?extid=23d7fcd204e3837866ff


Fixes: da58f90f ("netdevsim: Add devlink-trap support")
Signed-off-by: default avatarNikola Z. Ivanov <zlatistiv@gmail.com>
Reviewed-by: default avatarEric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260426201434.742030-1-zlatistiv@gmail.com


Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
parent 3618442d
Loading
Loading
Loading
Loading
+1 −1
Original line number Diff line number Diff line
@@ -829,7 +829,7 @@ static struct sk_buff *nsim_dev_trap_skb_build(void)
	skb->protocol = htons(ETH_P_IP);

	skb_set_network_header(skb, skb->len);
	iph = skb_put(skb, sizeof(struct iphdr));
	iph = skb_put_zero(skb, sizeof(struct iphdr));
	iph->protocol = IPPROTO_UDP;
	iph->saddr = in_aton("192.0.2.1");
	iph->daddr = in_aton("198.51.100.1");