From: syzbot ci <syzbot+ci580e1d9fe98861cc@syzkaller.appspotmail.com>
To: syzkaller-upstream-moderation@googlegroups.com
Cc: syzbot@lists.linux.dev
Subject: [moderation/CI] Re: ip: validate options before echoing them
Date: Wed, 02 Sep 2026 14:33:19 -0700 [thread overview]
Message-ID: <6a98961f.9266084e.bf0d7.0010.GAE@google.com> (raw)
syzbot ci has tested the following series
[v3] ip: validate options before echoing them
https://lore.kernel.org/all/20260902055802.3724915-1-4ncienth@gmail.com
* [PATCH net v3] ip: validate options before echoing them
and found the following issue:
WARNING in __ip_options_echo
Full report is available here:
https://ci.syzbot.org/series/58d17295-c695-49b2-826d-b0fe305808e9
***
WARNING in __ip_options_echo
tree: linux-next
URL: https://kernel.googlesource.com/pub/scm/linux/kernel/git/next/linux-next
base: 70f3995830d3f1e79faa14eb0605914f778feca9
arch: amd64
compiler: Debian clang version 22.1.8 (++20260613092233+e80beda6e255-1~exp1~20260613092250.77), Debian LLD 22.1.8
config: https://ci.syzbot.org/builds/9a250d6c-0a45-4565-bbc0-cac6bc3e42ee/config
syz repro: https://ci.syzbot.org/findings/5fa937c9-0c72-4a82-8221-cd01d8dc83d5/syz_repro
------------[ cut here ]------------
len > ((int)(~0U >> 1))
WARNING: ./include/linux/skbuff.h:2864 at pskb_may_pull_reason include/linux/skbuff.h:2864 [inline], CPU#1: syz.0.17/5791
WARNING: ./include/linux/skbuff.h:2864 at pskb_network_may_pull_reason include/linux/skbuff.h:3294 [inline], CPU#1: syz.0.17/5791
WARNING: ./include/linux/skbuff.h:2864 at pskb_network_may_pull include/linux/skbuff.h:3299 [inline], CPU#1: syz.0.17/5791
WARNING: ./include/linux/skbuff.h:2864 at __ip_options_echo+0x10e4/0x1870 net/ipv4/ip_options.c:115, CPU#1: syz.0.17/5791
Modules linked in:
CPU: 1 UID: 0 PID: 5791 Comm: syz.0.17 Not tainted syzkaller #0 PREEMPT(full)
Hardware name: QEMU Standard PC (Q35 + ICH9, 2009), BIOS 1.16.2-debian-1.16.2-1 04/01/2014
RIP: 0010:pskb_may_pull_reason include/linux/skbuff.h:2864 [inline]
RIP: 0010:pskb_network_may_pull_reason include/linux/skbuff.h:3294 [inline]
RIP: 0010:pskb_network_may_pull include/linux/skbuff.h:3299 [inline]
RIP: 0010:__ip_options_echo+0x10e4/0x1870 net/ipv4/ip_options.c:115
Code: 00 00 00 fc ff df 43 0f b6 04 3c 84 c0 0f 85 64 07 00 00 41 88 1e 4c 8b 64 24 10 41 83 c4 04 e9 a7 fe ff ff e8 7d 13 84 f7 90 <0f> 0b 90 e9 35 f1 ff ff 44 89 e7 44 89 f6 e8 79 15 84 f7 45 39 f4
RSP: 0018:ffffc90004efef40 EFLAGS: 00010293
RAX: ffffffff8a43a023 RBX: ffff8881b89a6b58 RCX: ffff888111125a00
RDX: 0000000000000000 RSI: 00000000fffffff8 RDI: 0000000000000000
RBP: ffffc90004eff070 R08: ffffc90004eff2c7 R09: 0000000000000000
R10: ffffc90004eff2b8 R11: fffff520009dfe59 R12: 00000000fffffff8
R13: ffff8881b89a6a80 R14: ffff8881b89a6b00 R15: 000000000000001c
FS: 00007f39f8af86c0(0000) GS:ffff8882a8cdf000(0000) knlGS:0000000000000000
CS: 0010 DS: 0000 ES: 0000 CR0: 0000000080050033
CR2: 00007f39f8af7ff8 CR3: 0000000112830000 CR4: 00000000000006f0
Call Trace:
<TASK>
ip_options_echo include/net/ip.h:798 [inline]
icmp_reply+0x2da/0xc90 net/ipv4/icmp.c:429
icmp_timestamp+0x246/0x370 net/ipv4/icmp.c:1430
icmp_rcv+0xd33/0x1290 net/ipv4/icmp.c:1543
ip_protocol_deliver_rcu+0x2dc/0x440 net/ipv4/ip_input.c:207
ip_local_deliver_finish+0x3bb/0x6f0 net/ipv4/ip_input.c:241
NF_HOOK+0x336/0x3c0 include/linux/netfilter.h:325
NF_HOOK+0x336/0x3c0 include/linux/netfilter.h:325
__netif_receive_skb_one_core net/core/dev.c:6264 [inline]
__netif_receive_skb net/core/dev.c:6377 [inline]
netif_receive_skb_internal net/core/dev.c:6463 [inline]
netif_receive_skb+0x45b/0xbf0 net/core/dev.c:6522
tun_rx_batched+0x1de/0x790 drivers/net/tun.c:1571
tun_get_user+0x2be0/0x44d0 drivers/net/tun.c:2045
tun_chr_write_iter+0x113/0x200 drivers/net/tun.c:2091
new_sync_write fs/read_write.c:595 [inline]
vfs_write+0x612/0xba0 fs/read_write.c:687
ksys_write+0x150/0x270 fs/read_write.c:739
do_syscall_x64 arch/x86/entry/syscall_64.c:61 [inline]
do_syscall_64+0x166/0x520 arch/x86/entry/syscall_64.c:84
entry_SYSCALL_64_after_hwframe+0x77/0x7f
RIP: 0033:0x7f39f7b5e98e
Code: 08 0f 85 a5 a8 ff ff 49 89 fb 48 89 f0 48 89 d7 48 89 ce 4c 89 c2 4d 89 ca 4c 8b 44 24 08 4c 8b 4c 24 10 4c 89 5c 24 08 0f 05 <c3> 66 2e 0f 1f 84 00 00 00 00 00 0f 1f 80 00 00 00 00 48 83 ec 08
RSP: 002b:00007f39f8af7fb8 EFLAGS: 00000246 ORIG_RAX: 0000000000000001
RAX: ffffffffffffffda RBX: 00007f39f8af86c0 RCX: 00007f39f7b5e98e
RDX: 000000000000003e RSI: 0000200000000780 RDI: 00000000000000c8
RBP: 00007f39f7c35024 R08: 0000000000000000 R09: 0000000000000000
R10: 0000000000000000 R11: 0000000000000246 R12: 0000000000000000
R13: 00007f39f7e26038 R14: 00007f39f7e25fa0 R15: 00007fff66b2b028
</TASK>
***
If these findings have caused you to resend the series or submit a
separate fix, please add the following tag to your commit message:
Tested-by: syzbot@syzkaller.appspotmail.com
---
This report is generated by a bot. It may contain errors.
syzbot ci engineers can be reached at syzkaller@googlegroups.com.
To test a fix for this bug, please reply with `#syz test`
(on a separate line) and attach the patch to the email.
Notes:
- The patch will be applied on top of the tested series (as an
incremental fix).
- To test a new version of the whole series, please send it directly
to syzbot@lists.linux.dev.
- Arguments like custom git repos and branches are not supported.
The email will later be sent to:
[4ncienth@gmail.com davem@davemloft.net dsahern@kernel.org edumazet@google.com horms@kernel.org idosch@nvidia.com kuba@kernel.org linux-kernel@vger.kernel.org netdev@vger.kernel.org pabeni@redhat.com]
If the report looks fine to you, reply with:
#syz upstream
If the report is a false positive, reply with
#syz invalid
next reply other threads:[~2026-09-02 21:33 UTC|newest]
Thread overview: 2+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-02 21:33 syzbot ci [this message]
2026-09-02 22:02 ` [moderation/CI] Re: ip: validate options before echoing them Aleksandr Nogikh
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=6a98961f.9266084e.bf0d7.0010.GAE@google.com \
--to=syzbot+ci580e1d9fe98861cc@syzkaller.appspotmail.com \
--cc=syzbot@lists.linux.dev \
--cc=syzkaller-upstream-moderation@googlegroups.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.