Thread (4 messages) 4 messages, 3 authors, 6d ago

RE: [PATCH net v2] tipc: fix memory leaks in bundle and fragment paths

flat view

From: Tung Quang Nguyen <tung.quang.nguyen@est.tech>
Date: 2026-10-05 01:49:15

Subject: [PATCH net v2] tipc: fix memory leaks in bundle and fragment paths

From: xiaoshoukui <redacted>

In tipc_data_input(), recognized internal control message users (such as
MSG_BUNDLER, TUNNEL_PROTOCOL, MSG_FRAGMENTER, and
BCAST_PROTOCOL) return false WITHOUT releasing the skb via kfree_skb().

However, callers in the bundle extraction and fragment reassembly receive
paths currently ignore the return value of tipc_data_input().
This leads to memory leaks in the following scenarios:

1. Nested Bundle Path:
  When an outer MSG_BUNDLER message contains a structurally valid
  inner MSG_BUNDLER payload, tipc_msg_extract() allocates and
  extracts the inner skb. tipc_data_input() inspects the inner
  header, sees MSG_BUNDLER, and returns false without consuming or
  freeing the skb. Because the extraction loop ignores the return
  value, the inner skb is leaked.

2. Fragment Reassembly Path:
  When reassembly completes in tipc_buf_append(), the reassembled
  skb may carry msg_user == MSG_FRAGMENTER. tipc_data_input()
  inspects the reassembled skb, sees MSG_FRAGMENTER, and returns
  false without consuming or freeing it. The fragment completion path
  ignores the return value, leaking the reassembled skb.
This cannot happen as I explained.
We do not accept a bogus fix that causes regression.
Please drop your patch.

--
pw-bot: rejected
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help