net/sched: em_canid: fix uninit-value in em_canid_match
authorShaurya Rane <ssrane_b23@ee.vjti.ac.in>
Wed, 26 Nov 2025 08:57:18 +0000 (14:27 +0530)
committerMarc Kleine-Budde <mkl@pengutronix.de>
Wed, 26 Nov 2025 15:28:10 +0000 (16:28 +0100)
commit0c922106d7a58d106c6a5c52a741ae101cfaf088
tree6e6279bb8bcb7e465c2c516878a81cf15c3d6c81
parent6d849ff573722afcf5508d2800017bdd40f27eb9
net/sched: em_canid: fix uninit-value in em_canid_match

Use pskb_may_pull() to ensure a complete CAN frame is present in the
linear data buffer before reading the CAN ID. A simple skb->len check
is insufficient because it only verifies the total data length but does
not guarantee the data is present in skb->data (it could be in
fragments).

pskb_may_pull() both validates the length and pulls fragmented data
into the linear buffer if necessary, making it safe to directly
access skb->data.

Reported-by: syzbot+5d8269a1e099279152bc@syzkaller.appspotmail.com
Closes: https://syzkaller.appspot.com/bug?extid=5d8269a1e099279152bc
Fixes: f057bbb6f9ed ("net: em_canid: Ematch rule to match CAN frames according to their identifiers")
Signed-off-by: Shaurya Rane <ssrane_b23@ee.vjti.ac.in>
Link: https://patch.msgid.link/20251126085718.50808-1-ssranevjti@gmail.com
Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
net/sched/em_canid.c