Commit ab9414ed70bd for kernel

commit ab9414ed70bd783e902a85c350620dee269bcb2b
Author: Josef Bacik <josef@toxicpanda.com>
Date:   Wed Oct 7 17:29:34 2026 +0000

    net: skbuff: don't leave stale bytes in skb_copy_and_csum_bits()

    When skb_copy_and_csum_bits() reaches unreadable frags it returns 0
    after copying only the linear part, and the rest of the caller's buffer
    is left as it was.  The callers copy into a buffer that is about to go
    out on the wire: an ICMP error quoting the offending packet, or a
    driver's TX bounce buffer in skb_copy_and_csum_dev().  Neither buffer
    is zeroed beforehand, so whatever was in memory there gets sent.

    Zero the part of the buffer we didn't fill.  The checksum usually
    won't match the data any more, so the receiver will usually drop the
    packet, but either way it no longer carries anything it shouldn't.
    Only zero for a positive @len, a negative one from a broken caller must
    not turn into a huge memset().

    Fixes: 65249feb6b3d ("net: add support for skbs with unreadable frags")
    Cc: stable@vger.kernel.org
    Signed-off-by: Josef Bacik <josef@toxicpanda.com>
    Reviewed-by: Mina Almasry <almasrymina@google.com>
    Link: https://patch.msgid.link/20261007-b4-skb-copy-csum-stale-bytes-v1-1-adbbde033fb3@toxicpanda.com
    Signed-off-by: Jakub Kicinski <kuba@kernel.org>

diff --git a/net/core/skbuff.c b/net/core/skbuff.c
index 4aea06d5167d..41beaf625421 100644
--- a/net/core/skbuff.c
+++ b/net/core/skbuff.c
@@ -3633,8 +3633,12 @@ __wsum skb_copy_and_csum_bits(const struct sk_buff *skb, int offset,
 		pos	= copy;
 	}

-	if (!skb_frags_readable(skb))
+	if (!skb_frags_readable(skb)) {
+		/* Don't hand the caller a buffer with stale bytes in it. */
+		if (len > 0)
+			memset(to, 0, len);
 		return 0;
+	}

 	for (i = 0; i < skb_shinfo(skb)->nr_frags; i++) {
 		int end;