Commit 93ccaf1c26e2 for kernel

commit 93ccaf1c26e2133396173b76a071e59024daa622
Author: Josef Bacik <josef@toxicpanda.com>
Date:   Wed Oct 7 17:57:32 2026 +0000

    xen/netfront: don't leak the skb when xennet_fill_frags() fails

    When a response chain has more slots than fit in the skb's frags,
    xennet_fill_frags() returns an error and xennet_poll() jumps to its
    error path.  That path moves what's left on tmpq to errq to be freed,
    but the skb being filled was already dequeued from tmpq, so it's never
    freed.  Each chain that overflows leaks the skb and the pages attached
    to it as frags, and the backend decides how many slots it sends.

    Put the skb back on tmpq before taking the error path, like the
    xennet_set_skb_gso() failure just above it does.

    Fixes: ad4f15dc2c70 ("xen/netfront: don't bug in case of too many frags")
    Cc: stable@vger.kernel.org
    Signed-off-by: Josef Bacik <josef@toxicpanda.com>
    Reviewed-by: Juergen Gross <jgross@suse.com>
    Link: https://patch.msgid.link/20261007-b4-xen-netfront-fill-frags-leak-v1-1-a8a01ff9cd52@toxicpanda.com
    Signed-off-by: Jakub Kicinski <kuba@kernel.org>

diff --git a/drivers/net/xen-netfront.c b/drivers/net/xen-netfront.c
index d269457e839e..fdcb91042f29 100644
--- a/drivers/net/xen-netfront.c
+++ b/drivers/net/xen-netfront.c
@@ -1346,8 +1346,10 @@ static int xennet_poll(struct napi_struct *napi, int budget)
 		skb->data_len = rx->status;
 		skb->len += rx->status;

-		if (unlikely(xennet_fill_frags(queue, skb, &tmpq)))
+		if (unlikely(xennet_fill_frags(queue, skb, &tmpq))) {
+			__skb_queue_head(&tmpq, skb);
 			goto err;
+		}

 		if (rx->flags & XEN_NETRXF_csum_blank)
 			skb->ip_summed = CHECKSUM_PARTIAL;