From: Baolin Wang <hidden> Date: 2019-09-03 06:57:10
From: Eric Dumazet <edumazet@google.com>
Since ip6frag_expire_frag_queue() now pulls the head skb
from frag queue, we should no longer use skb_get(), since
this leads to an skb leak.
Stefan Bader initially reported a problem in 4.4.stable [1] caused
by the skb_get(), so this patch should also fix this issue.
296583.091021] kernel BUG at /build/linux-6VmqmP/linux-4.4.0/net/core/skbuff.c:1207!
[296583.091734] Call Trace:
[296583.091749] [<ffffffff81740e50>] __pskb_pull_tail+0x50/0x350
[296583.091764] [<ffffffff8183939a>] _decode_session6+0x26a/0x400
[296583.091779] [<ffffffff817ec719>] __xfrm_decode_session+0x39/0x50
[296583.091795] [<ffffffff818239d0>] icmpv6_route_lookup+0xf0/0x1c0
[296583.091809] [<ffffffff81824421>] icmp6_send+0x5e1/0x940
[296583.091823] [<ffffffff81753238>] ? __netif_receive_skb+0x18/0x60
[296583.091838] [<ffffffff817532b2>] ? netif_receive_skb_internal+0x32/0xa0
[296583.091858] [<ffffffffc0199f74>] ? ixgbe_clean_rx_irq+0x594/0xac0 [ixgbe]
[296583.091876] [<ffffffffc04eb260>] ? nf_ct_net_exit+0x50/0x50 [nf_defrag_ipv6]
[296583.091893] [<ffffffff8183d431>] icmpv6_send+0x21/0x30
[296583.091906] [<ffffffff8182b500>] ip6_expire_frag_queue+0xe0/0x120
[296583.091921] [<ffffffffc04eb27f>] nf_ct_frag6_expire+0x1f/0x30 [nf_defrag_ipv6]
[296583.091938] [<ffffffff810f3b57>] call_timer_fn+0x37/0x140
[296583.091951] [<ffffffffc04eb260>] ? nf_ct_net_exit+0x50/0x50 [nf_defrag_ipv6]
[296583.091968] [<ffffffff810f5464>] run_timer_softirq+0x234/0x330
[296583.091982] [<ffffffff8108a339>] __do_softirq+0x109/0x2b0
Fixes: d4289fcc9b16 ("net: IP6 defrag: use rbtrees for IPv6 defrag")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Stefan Bader <redacted>
Cc: Peter Oskolkov <redacted>
Cc: Florian Westphal <fw@strlen.de>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Baolin Wang <redacted>
---
include/net/ipv6_frag.h | 1 -
1 file changed, 1 deletion(-)
From: Baolin Wang <hidden> Date: 2019-09-03 06:58:54
From: Hariprasad Kelam <redacted>
This patch removes NULL checks before calling kfree.
fixes below issues reported by coccicheck
net/sctp/sm_make_chunk.c:2586:3-8: WARNING: NULL check before some
freeing functions is not needed.
net/sctp/sm_make_chunk.c:2652:3-8: WARNING: NULL check before some
freeing functions is not needed.
net/sctp/sm_make_chunk.c:2667:3-8: WARNING: NULL check before some
freeing functions is not needed.
net/sctp/sm_make_chunk.c:2684:3-8: WARNING: NULL check before some
freeing functions is not needed.
Signed-off-by: Hariprasad Kelam <redacted>
Acked-by: Marcelo Ricardo Leitner <marcelo.leitner@gmail.com>
Acked-by: Neil Horman <nhorman@tuxdriver.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Baolin Wang <redacted>
---
net/sctp/sm_make_chunk.c | 12 ++++--------
1 file changed, 4 insertions(+), 8 deletions(-)
@@ -2586,8 +2586,7 @@ static int sctp_process_param(struct sctp_association *asoc,caseSCTP_PARAM_STATE_COOKIE:asoc->peer.cookie_len=ntohs(param.p->length)-sizeof(structsctp_paramhdr);-if(asoc->peer.cookie)-kfree(asoc->peer.cookie);+kfree(asoc->peer.cookie);asoc->peer.cookie=kmemdup(param.cookie->body,asoc->peer.cookie_len,gfp);if(!asoc->peer.cookie)retval=0;
@@ -2652,8 +2651,7 @@ static int sctp_process_param(struct sctp_association *asoc,gotofall_through;/* Save peer's random parameter */-if(asoc->peer.peer_random)-kfree(asoc->peer.peer_random);+kfree(asoc->peer.peer_random);asoc->peer.peer_random=kmemdup(param.p,ntohs(param.p->length),gfp);if(!asoc->peer.peer_random){
@@ -2667,8 +2665,7 @@ static int sctp_process_param(struct sctp_association *asoc,gotofall_through;/* Save peer's HMAC list */-if(asoc->peer.peer_hmacs)-kfree(asoc->peer.peer_hmacs);+kfree(asoc->peer.peer_hmacs);asoc->peer.peer_hmacs=kmemdup(param.p,ntohs(param.p->length),gfp);if(!asoc->peer.peer_hmacs){
@@ -2684,8 +2681,7 @@ static int sctp_process_param(struct sctp_association *asoc,if(!ep->auth_enable)gotofall_through;-if(asoc->peer.peer_chunks)-kfree(asoc->peer.peer_chunks);+kfree(asoc->peer.peer_chunks);asoc->peer.peer_chunks=kmemdup(param.p,ntohs(param.p->length),gfp);if(!asoc->peer.peer_chunks)
From: Baolin Wang <hidden> Date: 2019-09-03 07:01:11
From: Eric Biggers <redacted>
Commit 0e5a610b5ca5 ("ppp: mppe: switch to RC4 library interface"),
which was merged through the crypto tree for v5.3, changed ppp_mppe.c to
use the new arc4_crypt() library function rather than access RC4 through
the dynamic crypto_skcipher API.
Meanwhile commit aad1dcc4f011 ("ppp: mppe: Add softdep to arc4") was
merged through the net tree and added a module soft-dependency on "arc4".
The latter commit no longer makes sense because the code now uses the
"libarc4" module rather than "arc4", and also due to the direct use of
arc4_crypt(), no module soft-dependency is required.
So revert the latter commit.
Cc: Takashi Iwai <redacted>
Cc: Ard Biesheuvel <redacted>
Signed-off-by: Eric Biggers <redacted>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Baolin Wang <redacted>
---
drivers/net/ppp/ppp_mppe.c | 1 -
1 file changed, 1 deletion(-)
On Tue, Sep 03, 2019 at 02:58:16PM +0800, Baolin Wang wrote:
From: Hariprasad Kelam <redacted>
This patch removes NULL checks before calling kfree.
fixes below issues reported by coccicheck
net/sctp/sm_make_chunk.c:2586:3-8: WARNING: NULL check before some
freeing functions is not needed.
net/sctp/sm_make_chunk.c:2652:3-8: WARNING: NULL check before some
freeing functions is not needed.
net/sctp/sm_make_chunk.c:2667:3-8: WARNING: NULL check before some
freeing functions is not needed.
net/sctp/sm_make_chunk.c:2684:3-8: WARNING: NULL check before some
freeing functions is not needed.
Hi. This doesn't seem the kind of patch that should be backported to
such old/stable releases. After all, it's just a cleanup.
Marcelo
On Tue, Sep 03, 2019 at 11:52:06AM -0300, Marcelo Ricardo Leitner wrote:
On Tue, Sep 03, 2019 at 02:58:16PM +0800, Baolin Wang wrote:
quoted
From: Hariprasad Kelam <redacted>
This patch removes NULL checks before calling kfree.
fixes below issues reported by coccicheck
net/sctp/sm_make_chunk.c:2586:3-8: WARNING: NULL check before some
freeing functions is not needed.
net/sctp/sm_make_chunk.c:2652:3-8: WARNING: NULL check before some
freeing functions is not needed.
net/sctp/sm_make_chunk.c:2667:3-8: WARNING: NULL check before some
freeing functions is not needed.
net/sctp/sm_make_chunk.c:2684:3-8: WARNING: NULL check before some
freeing functions is not needed.
Hi. This doesn't seem the kind of patch that should be backported to
such old/stable releases. After all, it's just a cleanup.
I agree, this does not seem necessary _unless_ it is needed for a later
real fix.
thanks,
greg k-h
From: Baolin Wang <hidden> Date: 2019-09-04 02:38:54
On Wed, 4 Sep 2019 at 02:33, Greg KH [off-list ref] wrote:
On Tue, Sep 03, 2019 at 11:52:06AM -0300, Marcelo Ricardo Leitner wrote:
quoted
On Tue, Sep 03, 2019 at 02:58:16PM +0800, Baolin Wang wrote:
quoted
From: Hariprasad Kelam <redacted>
This patch removes NULL checks before calling kfree.
fixes below issues reported by coccicheck
net/sctp/sm_make_chunk.c:2586:3-8: WARNING: NULL check before some
freeing functions is not needed.
net/sctp/sm_make_chunk.c:2652:3-8: WARNING: NULL check before some
freeing functions is not needed.
net/sctp/sm_make_chunk.c:2667:3-8: WARNING: NULL check before some
freeing functions is not needed.
net/sctp/sm_make_chunk.c:2684:3-8: WARNING: NULL check before some
freeing functions is not needed.
Hi. This doesn't seem the kind of patch that should be backported to
such old/stable releases. After all, it's just a cleanup.
I agree, this does not seem necessary _unless_ it is needed for a later
real fix.
It can remove warnings from our product kernel since this patch
(c4964bfaf433 sctp: Free cookie before we memdup a new one) was merged
into stable, we still need backport it to our product kernel manually.
But if you still think this is unnecessary, please ignore this patch.
Thanks for your comments.
--
Baolin Wang
Best Regards