Thread (2 messages) flat view 2 messages, 2 authors, 2021-06-04

Re: [PATCH net] sch_htb: fix refcount leak in htb_parent_to_leaf_offload

From: patchwork-bot+netdevbpf@kernel.org
Date: 2021-06-04 21:50:09

Hello:

This patch was applied to netdev/net.git (refs/heads/master):

On Fri, 4 Jun 2021 19:03:18 +0800 you wrote:
From: Yunjian Wang <redacted>

The commit ae81feb7338c ("sch_htb: fix null pointer dereference
on a null new_q") fixes a NULL pointer dereference bug, but it
is not correct.

Because htb_graft_helper properly handles the case when new_q
is NULL, and after the previous patch by skipping this call
which creates an inconsistency : dev_queue->qdisc will still
point to the old qdisc, but cl->parent->leaf.q will point to
the new one (which will be noop_qdisc, because new_q was NULL).
The code is based on an assumption that these two pointers are
the same, so it can lead to refcount leaks.

[...]
Here is the summary with links:
  - [net] sch_htb: fix refcount leak in htb_parent_to_leaf_offload
    https://git.kernel.org/netdev/net/c/944d671d5faa

You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html

Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help