From: David Ahern <dsahern@kernel.org>
To: Eric Dumazet <edumazet@google.com>,
"David S . Miller" <davem@davemloft.net>,
Jakub Kicinski <kuba@kernel.org>, Paolo Abeni <pabeni@redhat.com>
Cc: Simon Horman <horms@kernel.org>, Ido Schimmel <idosch@nvidia.com>,
netdev@vger.kernel.org, eric.dumazet@gmail.com,
syzbot+6d2762674103618994b0@syzkaller.appspotmail.com,
Peilin He <he.peilin@zte.com.cn>, xu xin <xu.xin16@zte.com.cn>,
Steven Rostedt <rostedt@goodmis.org>
Subject: Re: [PATCH net] net: icmp: avoid invalid transport header access in icmp_send tracepoint
Date: Tue, 25 Aug 2026 08:48:48 -0600 [thread overview]
Message-ID: <0d562eeb-7292-4edc-b499-5e32fbb6ee3d@kernel.org> (raw)
In-Reply-To: <20260825084551.1562967-1-edumazet@google.com>
On 8/25/26 2:45 AM, Eric Dumazet wrote:
> syzbot reported a WARNING triggered by DEBUG_NET_WARN_ON_ONCE():
>
> WARNING: at skb_transport_header include/linux/skbuff.h:3087 [inline]
> WARNING: at udp_hdr include/linux/udp.h:23 [inline]
> WARNING: at do_trace_event_raw_event_icmp_send include/trace/events/icmp.h:30 [inline]
> WARNING: at trace_event_raw_event_icmp_send+0x48c/0x6ec include/trace/events/icmp.h:11
> Call trace:
> skb_transport_header include/linux/skbuff.h:3087 [inline]
> udp_hdr include/linux/udp.h:23 [inline]
> do_trace_event_raw_event_icmp_send include/trace/events/icmp.h:30 [inline]
> trace_event_raw_event_icmp_send+0x48c/0x6ec include/trace/events/icmp.h:11
> __traceiter_icmp_send include/trace/events/icmp.h:11 [inline]
> __do_trace_icmp_send include/trace/events/icmp.h:11 [inline]
> trace_icmp_send+0x320/0x49c include/trace/events/icmp.h:11
> __icmp_send+0xcfc/0x11d8 net/ipv4/icmp.c:1013
> ipv4_send_dest_unreach net/ipv4/route.c:1280 [inline]
> ipv4_link_failure+0x57c/0x8dc net/ipv4/route.c:1287
> dst_link_failure include/net/dst.h:438 [inline]
> vti_tunnel_xmit+0xe40/0x17a4 net/ipv4/ip_vti.c:307
>
> TP_fast_assign() unconditionally calls udp_hdr(skb) before checking
> whether the packet is UDP. Furthermore, __icmp_send() can be invoked
> from paths (e.g., link failures, ARP errors, forwarding, AF_PACKET)
> where skb->transport_header was never initialized (~0U).
>
> Under CONFIG_DEBUG_NET=y, calling skb_transport_header(skb) triggers
> DEBUG_NET_WARN_ON_ONCE(!skb_transport_header_was_set(skb)).
>
> Fix this by:
> 1. Only parsing transport info when iph->protocol == IPPROTO_UDP.
> 2. Using skb_header_pointer() at skb_network_offset(skb) + (iph->ihl << 2)
> to safely fetch the UDP header without assuming transport_header is set.
>
> Fixes: db3efdcf70c7 ("net/ipv4: add tracepoint for icmp_send")
> Reported-by: syzbot+6d2762674103618994b0@syzkaller.appspotmail.com
> Closes: https://lore.kernel.org/netdev/6a8d5538.91706f20.ef82.0009.GAE@google.com/T/#u
> Signed-off-by: Eric Dumazet <edumazet@google.com>
> Cc: Peilin He <he.peilin@zte.com.cn>
> Cc: xu xin <xu.xin16@zte.com.cn>
> Cc: Steven Rostedt <rostedt@goodmis.org>
> ---
> include/trace/events/icmp.h | 13 ++++++++-----
> 1 file changed, 8 insertions(+), 5 deletions(-)
>
> diff --git a/include/trace/events/icmp.h b/include/trace/events/icmp.h
> index 09ae115099dfe25616b6c74d5b92be1af4acff55..6937b778ae54dbf4442b127957a017da3551aaff 100644
> --- a/include/trace/events/icmp.h
> +++ b/include/trace/events/icmp.h
> @@ -27,17 +27,20 @@ TRACE_EVENT(icmp_send,
>
> TP_fast_assign(
> struct iphdr *iph = ip_hdr(skb);
> - struct udphdr *uh = udp_hdr(skb);
> - int proto_4 = iph->protocol;
> + struct udphdr _uh, *uh = NULL;
> __be32 *p32;
>
> __entry->skbaddr = skb;
> __entry->type = type;
> __entry->code = code;
>
> - if (proto_4 != IPPROTO_UDP || (u8 *)uh < skb->head ||
> - (u8 *)uh + sizeof(struct udphdr)
> - > skb_tail_pointer(skb)) {
> + if (iph->protocol == IPPROTO_UDP)
> + uh = skb_header_pointer(skb,
> + skb_network_offset(skb) +
> + (iph->ihl << 2),
> + sizeof(_uh), &_uh);
> +
> + if (!uh) {
> __entry->sport = 0;
> __entry->dport = 0;
> __entry->ulen = 0;
This code change looks fine, so:
Reviewed-by: David Ahern <dsahern@kernel.org>
But really, why not drop the tracepoint entirely and have the author of
the original patch send a new version that acknowledges icmp's are sent
for other transport protocols?
next prev parent reply other threads:[~2026-08-25 14:48 UTC|newest]
Thread overview: 6+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-08-25 8:45 [PATCH net] net: icmp: avoid invalid transport header access in icmp_send tracepoint Eric Dumazet
2026-08-25 9:43 ` Jiayuan Chen
2026-08-25 12:50 ` Steven Rostedt
2026-08-25 14:11 ` Eric Dumazet
2026-08-25 14:48 ` David Ahern [this message]
2026-08-28 22:10 ` patchwork-bot+netdevbpf
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=0d562eeb-7292-4edc-b499-5e32fbb6ee3d@kernel.org \
--to=dsahern@kernel.org \
--cc=davem@davemloft.net \
--cc=edumazet@google.com \
--cc=eric.dumazet@gmail.com \
--cc=he.peilin@zte.com.cn \
--cc=horms@kernel.org \
--cc=idosch@nvidia.com \
--cc=kuba@kernel.org \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=rostedt@goodmis.org \
--cc=syzbot+6d2762674103618994b0@syzkaller.appspotmail.com \
--cc=xu.xin16@zte.com.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.