The patched kernel (this patch on 28924df2a08f) does not panic on the
attached reproducer.

Tested-by: Farhad Alemi <[email protected]>




On Fri, Aug 28, 2026 at 12:46 AM Eric Dumazet <[email protected]> wrote:
>
> On Fri, Aug 28, 2026 at 9:22 AM Farhad Alemi <[email protected]> 
> wrote:
> >
> > Hello,
> >
> > As part of the kernel research at ASU's SEFCOM
> > lab, we hit the crash below. Crash reports can be found here:
> >
> >   
> > https://github.com/farhad-alemi/public_bug_reports/tree/main/182-warning-in-lowpan-compress-addr-64/
> >
> >   WARNING: net/6lowpan/iphc.c:937 at
> > lowpan_iphc_compress_802154_lladdr net/6lowpan/iphc.c:937 [inline],
> > CPU#0: syz.9.76/13660
> >   WARNING: net/6lowpan/iphc.c:937 at
> > lowpan_compress_addr_64+0x4be/0x9c0 net/6lowpan/iphc.c:952, CPU#0:
> > syz.9.76/13660
> >   RIP: 0010:lowpan_compress_addr_64+0x4be/0x9c0 net/6lowpan/iphc.c:952
> >   Call Trace:
> >    lowpan_compress_addr_64+0x4be/0x9c0 net/6lowpan/iphc.c:952
> >    lowpan_header_compress+0xeef/0x1ef0 net/6lowpan/iphc.c:1242
> >    lowpan_header net/ieee802154/6lowpan/tx.c:234 [inline]
> >    lowpan_xmit+0x4c6/0x1420 net/ieee802154/6lowpan/tx.c:282
> >    dev_hard_start_xmit+0x23b/0x620 net/core/dev.c:3904
> >    __dev_queue_xmit+0x11e7/0x3250 net/core/dev.c:4870
> >    packet_snd net/packet/af_packet.c:3082 [inline]
> >    packet_sendmsg+0x3d9b/0x5150 net/packet/af_packet.c:3114
> >   Kernel panic - not syncing: kernel: panic_on_warn set ...
> >
> > Our reproducer.c is available upon request.
> >
> > Happy to test a patch if that would help.
>
> Thanks for the report.
>
> All these WARN_ON_ONCE() are bogus in modern days (panic_on_warn being
> used by fuzzers)
> Developers probably used them to catch unexpected packets.
> Guess what, fuzzers do exactly that.
>
> Also lowpan_header_create() seems to incorrectly return 0 instead of an error.
>
> Can you try:
>
> diff --git a/net/6lowpan/iphc.c b/net/6lowpan/iphc.c
> index 
> 37eaff3f7b6940b73924c38c360adf482d6cceab..dec04f63f1b2599a7291d020e662f4d129333c14
> 100644
> --- a/net/6lowpan/iphc.c
> +++ b/net/6lowpan/iphc.c
> @@ -180,8 +180,6 @@ lowpan_iphc_uncompress_802154_lladdr(struct
> in6_addr *ipaddr,
>                                         &addr->short_addr);
>                 break;
>         default:
> -               /* should never handled and filtered by 802154 6lowpan */
> -               WARN_ON_ONCE(1);
>                 break;
>         }
>  }
> @@ -820,8 +818,6 @@ lowpan_iphc_compress_ctx_802154_lladdr(const
> struct in6_addr *ipaddr,
>                         lladdr_compress = true;
>                 break;
>         default:
> -               /* should never handled and filtered by 802154 6lowpan */
> -               WARN_ON_ONCE(1);
>                 break;
>         }
>
> @@ -933,8 +929,6 @@ lowpan_iphc_compress_802154_lladdr(const struct
> in6_addr *ipaddr,
>                         lladdr_compress = true;
>                 break;
>         default:
> -               /* should never handled and filtered by 802154 6lowpan */
> -               WARN_ON_ONCE(1);
>                 break;
>         }
>
> diff --git a/net/ieee802154/6lowpan/tx.c b/net/ieee802154/6lowpan/tx.c
> index 
> 4df76ff50699ede5c187c9cca6f0cc10b19d2123..9bffe01cc448fcb993883748f359cc71b879a729
> 100644
> --- a/net/ieee802154/6lowpan/tx.c
> +++ b/net/ieee802154/6lowpan/tx.c
> @@ -47,7 +47,7 @@ int lowpan_header_create(struct sk_buff *skb, struct
> net_device *ldev,
>          * if this package isn't ipv6 one, where should it be routed?
>          */
>         if (type != ETH_P_IPV6)
> -               return 0;
> +               return -EINVAL;
>
>         /* intra-pan communication */
>         info->saddr.pan_id = wpan_dev->pan_id;

Attachment: reproducer.c
Description: Binary data

Reply via email to