RE: [PATCH net v2] tipc: fix memory leaks in bundle and fragment paths
flat view
From: Tung Quang Nguyen <tung.quang.nguyen@est.tech>
Date: 2026-10-05 01:49:15
Subject: [PATCH net v2] tipc: fix memory leaks in bundle and fragment paths From: xiaoshoukui <redacted> In tipc_data_input(), recognized internal control message users (such as MSG_BUNDLER, TUNNEL_PROTOCOL, MSG_FRAGMENTER, and BCAST_PROTOCOL) return false WITHOUT releasing the skb via kfree_skb(). However, callers in the bundle extraction and fragment reassembly receive paths currently ignore the return value of tipc_data_input(). This leads to memory leaks in the following scenarios: 1. Nested Bundle Path: When an outer MSG_BUNDLER message contains a structurally valid inner MSG_BUNDLER payload, tipc_msg_extract() allocates and extracts the inner skb. tipc_data_input() inspects the inner header, sees MSG_BUNDLER, and returns false without consuming or freeing the skb. Because the extraction loop ignores the return value, the inner skb is leaked. 2. Fragment Reassembly Path: When reassembly completes in tipc_buf_append(), the reassembled skb may carry msg_user == MSG_FRAGMENTER. tipc_data_input() inspects the reassembled skb, sees MSG_FRAGMENTER, and returns false without consuming or freeing it. The fragment completion path ignores the return value, leaking the reassembled skb.
This cannot happen as I explained. We do not accept a bogus fix that causes regression. Please drop your patch. -- pw-bot: rejected