)]}'
{
  "commit": "8b1f0af1fd5fd113432233ed8a3862ee7c30a84f",
  "tree": "2e3d5a9d516738f0d08e415f830e15592ba1f56c",
  "parents": [
    "bcf2573a68a808a5b54cadafa72b6672e662c2bf"
  ],
  "author": {
    "name": "Daehyeon Ko",
    "email": "4ncienth@gmail.com",
    "time": "Wed Sep 30 19:25:24 2026 +0900"
  },
  "committer": {
    "name": "Jakub Kicinski",
    "email": "kuba@kernel.org",
    "time": "Fri Oct 02 13:05:20 2026 -0700"
  },
  "message": "tcp: reject net_iov in zerocopy receive mapping hints\n\nAfter copying a readable prefix, receive_fallback_to_copy() asks\ntcp_zerocopy_set_hint_for_skb() where page mapping can resume. If the\nnext skb is unreadable, find_next_mappable_frag() passes its net_iov\nfragment to can_map_frag().\n\nskb_frag_page() returns NULL for a net_iov, but can_map_frag()\ndereferences it in PageCompound(). A v7.2 KASAN run on a connected TCP\nsocket with 64 readable bytes followed by a 4096-byte NET_IOV_DMABUF\nfragment reported:\n\n  BUG: KASAN: null-ptr-deref in can_map_frag\n  tcp_zerocopy_receive -\u003e can_map_frag\n  Kernel panic - not syncing: KASAN: panic_on_warn set\n\nThe diagnostic inserted the net_iov directly because the test host has\nno devmem-capable NIC. Hardware end-to-end reachability remains untested\nand requires CONFIG_NET_DEVMEM plus a supported DMA-buf-bound RX queue.\n\nReject all net_iov fragments before skb_frag_page(). This covers both\nDMABUF and IOURING net_iov types while leaving page-backed checks\nunchanged. With the guard, the same queue copied the readable prefix,\nreturned a 4096-byte skip hint, and completed without a fault.\n\nFixes: 9f6b619edf2e (\"net: support non paged skb frags\")\nCc: stable@vger.kernel.org\nSigned-off-by: Daehyeon Ko \u003c4ncienth@gmail.com\u003e\nReviewed-by: Mina Almasry \u003calmasrymina@google.com\u003e\nLink: https://patch.msgid.link/20260930102524.1659847-1-4ncienth@gmail.com\nSigned-off-by: Jakub Kicinski \u003ckuba@kernel.org\u003e\n",
  "tree_diff": [
    {
      "type": "modify",
      "old_id": "562752352afe4d7ab864c00b8562c8b8489a76f9",
      "old_mode": 33188,
      "old_path": "net/ipv4/tcp.c",
      "new_id": "87ef6d5cbfebaadcf88a5524c293f0348112661e",
      "new_mode": 33188,
      "new_path": "net/ipv4/tcp.c"
    }
  ]
}
