]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
udp: call skb_orphan() before skb_attempt_defer_free()
authorEric Dumazet <edumazet@google.com>
Mon, 5 Jan 2026 09:36:30 +0000 (09:36 +0000)
committerJakub Kicinski <kuba@kernel.org>
Wed, 7 Jan 2026 01:05:17 +0000 (17:05 -0800)
Standard UDP receive path does not use skb->destructor.

But skmsg layer does use it, since it calls skb_set_owner_sk_safe()
from udp_read_skb().

This then triggers this warning in skb_attempt_defer_free():

    DEBUG_NET_WARN_ON_ONCE(skb->destructor);

We must call skb_orphan() to fix this issue.

Fixes: 6471658dc66c ("udp: use skb_attempt_defer_free()")
Reported-by: syzbot+3e68572cf2286ce5ebe9@syzkaller.appspotmail.com
Closes: https://lore.kernel.org/netdev/695b83bd.050a0220.1c9965.002b.GAE@google.com/T/#u
Signed-off-by: Eric Dumazet <edumazet@google.com>
Link: https://patch.msgid.link/20260105093630.1976085-1-edumazet@google.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/ipv4/udp.c

index ffe074cb58658741f3cf2037cff9ea79e7f92742..ee63af0ef42ccbea754493d5f82bdf2ae4b8da7c 100644 (file)
@@ -1851,6 +1851,7 @@ void skb_consume_udp(struct sock *sk, struct sk_buff *skb, int len)
                sk_peek_offset_bwd(sk, len);
 
        if (!skb_shared(skb)) {
+               skb_orphan(skb);
                skb_attempt_defer_free(skb);
                return;
        }