[PATCH net v2] netdevsim: zero initialize struct iphdr in dummy sk_buff

Nikola Z. Ivanov posted 1 patch 1 month, 3 weeks ago
drivers/net/netdevsim/dev.c | 2 +-
1 file changed, 1 insertion(+), 1 deletion(-)
[PATCH net v2] netdevsim: zero initialize struct iphdr in dummy sk_buff
Posted by Nikola Z. Ivanov 1 month, 3 weeks ago
Syzbot reports a KMSAN uninit-value originating from
nsim_dev_trap_skb_build, with the allocation also
being performed in the same function.

Fix this by calling skb_put_zero instead of skb_put to
guarantee zero initialization of the whole IP header.

Closes: https://syzkaller.appspot.com/bug?extid=23d7fcd204e3837866ff
Fixes: da58f90f11f5 ("netdevsim: Add devlink-trap support")
Signed-off-by: Nikola Z. Ivanov <zlatistiv@gmail.com>
---
Changes since v1:
  - avoid unnecessary shuffling of struct member initialization.
  https://lore.kernel.org/netdev/20260421082005.74a3efb4@kernel.org/

 drivers/net/netdevsim/dev.c | 2 +-
 1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/netdevsim/dev.c b/drivers/net/netdevsim/dev.c
index 1e06e781c835..f00fc2f9ebde 100644
--- a/drivers/net/netdevsim/dev.c
+++ b/drivers/net/netdevsim/dev.c
@@ -829,7 +829,7 @@ static struct sk_buff *nsim_dev_trap_skb_build(void)
 	skb->protocol = htons(ETH_P_IP);
 
 	skb_set_network_header(skb, skb->len);
-	iph = skb_put(skb, sizeof(struct iphdr));
+	iph = skb_put_zero(skb, sizeof(struct iphdr));
 	iph->protocol = IPPROTO_UDP;
 	iph->saddr = in_aton("192.0.2.1");
 	iph->daddr = in_aton("198.51.100.1");
-- 
2.53.0
Re: [PATCH net v2] netdevsim: zero initialize struct iphdr in dummy sk_buff
Posted by Eric Dumazet 1 month, 2 weeks ago
On Sun, Apr 26, 2026 at 1:14 PM Nikola Z. Ivanov <zlatistiv@gmail.com> wrote:
>
> Syzbot reports a KMSAN uninit-value originating from
> nsim_dev_trap_skb_build, with the allocation also
> being performed in the same function.
>
> Fix this by calling skb_put_zero instead of skb_put to
> guarantee zero initialization of the whole IP header.
>
> Closes: https://syzkaller.appspot.com/bug?extid=23d7fcd204e3837866ff
> Fixes: da58f90f11f5 ("netdevsim: Add devlink-trap support")
> Signed-off-by: Nikola Z. Ivanov <zlatistiv@gmail.com>

Reviewed-by: Eric Dumazet <edumazet@google.com>