Path: csiph.com!eternal-september.org!feeder.eternal-september.org!aioe.org!bofh.it!news.nic.it!robomod From: Sasha Levin Newsgroups: linux.kernel Subject: Re: Bad backport of "net: Fix skb_set_peeked use-after-free bug" in 3.18.23 Date: Mon, 14 Dec 2015 18:20:02 +0100 Message-ID: References: X-Original-To: Paul Mackerras , linux-kernel@vger.kernel.org X-Enigmail-Draft-Status: N1110 User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Thunderbird/38.3.0 MIME-Version: 1.0 Content-Type: text/plain; charset=windows-1252 Content-Transfer-Encoding: 7bit X-Source-IP: userv0021.oracle.com [156.151.31.71] Sender: robomod@news.nic.it List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Approved: robomod@news.nic.it Lines: 24 Organization: linux.* mail to news gateway X-Original-Cc: Herbert Xu , "David S. Miller" , stable@vger.kernel.org X-Original-Date: Mon, 14 Dec 2015 12:15:47 -0500 X-Original-Message-ID: <566EF943.9070501@oracle.com> X-Original-References: <20151214024426.GA23275@iris.ozlabs.ibm.com> X-Original-Sender: linux-kernel-owner@vger.kernel.org Xref: csiph.com linux.kernel:1291358 On 12/13/2015 09:44 PM, Paul Mackerras wrote: > Commit d9a1133495b4 ("net: Fix skb_set_peeked use-after-free bug") in > 3.18.23 claims to be a backport of commit a0a2a6602496, but in fact > the patch is identical to commit 738ac1ebb96d ("net: Clone skb before > setting peeked flag"), which is the commit that introduces the > use-after-free bug that a0a2a6602496 fixes. > > The result is that we have been seeing crashes in __skb_recv_datagram > since I merged v3.18.24 into the kernel code we are using for a > product. Could someone fix this with an actual backport of > a0a2a6602496 please? Sorry about that, looks like my script has gone haywire :/ I've fixed it, pushed queue and will ship tomorrow after testing. Thanks, Sasha -- To unsubscribe from this list: send the line "unsubscribe linux-kernel" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html Please read the FAQ at http://www.tux.org/lkml/