Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1235613

[PATCH net 3/7] openvswitch: Fix skb leak in ovs_fragment()

From Joe Stringer <joestringer@nicira.com>
Newsgroups linux.kernel
Subject [PATCH net 3/7] openvswitch: Fix skb leak in ovs_fragment()
Date 2015-09-30 00:50 +0200
Message-ID <qebSG-3fs-15@gated-at.bofh.it> (permalink)
References <qebSG-3fs-5@gated-at.bofh.it>
Organization linux.* mail to news gateway

Show all headers | View raw


If ovs_fragment() was unable to fragment the skb due to an L2 header
that exceeds the supported length, skbs would be leaked. Fix the bug.

Fixes: 7f8a436 "openvswitch: Add conntrack action"
Signed-off-by: Joe Stringer <joestringer@nicira.com>
---
 net/openvswitch/actions.c | 13 +++++++++----
 1 file changed, 9 insertions(+), 4 deletions(-)

diff --git a/net/openvswitch/actions.c b/net/openvswitch/actions.c
index e23a61c..e1afbd1 100644
--- a/net/openvswitch/actions.c
+++ b/net/openvswitch/actions.c
@@ -684,7 +684,7 @@ static void ovs_fragment(struct vport *vport, struct sk_buff *skb, u16 mru,
 {
 	if (skb_network_offset(skb) > MAX_L2_LEN) {
 		OVS_NLERR(1, "L2 header too long to fragment");
-		return;
+		goto out;
 	}
 
 	if (ethertype == htons(ETH_P_IP)) {
@@ -708,8 +708,7 @@ static void ovs_fragment(struct vport *vport, struct sk_buff *skb, u16 mru,
 		struct rt6_info ovs_rt;
 
 		if (!v6ops) {
-			kfree_skb(skb);
-			return;
+			goto out;
 		}
 
 		prepare_frag(vport, skb);
@@ -728,8 +727,14 @@ static void ovs_fragment(struct vport *vport, struct sk_buff *skb, u16 mru,
 		WARN_ONCE(1, "Failed fragment ->%s: eth=%04x, MRU=%d, MTU=%d.",
 			  ovs_vport_name(vport), ntohs(ethertype), mru,
 			  vport->dev->mtu);
-		kfree_skb(skb);
+		goto out;
 	}
+
+	skb = NULL;
+
+out:
+	if (skb)
+		kfree_skb(skb);
 }
 
 static void do_output(struct datapath *dp, struct sk_buff *skb, int out_port,
-- 
2.1.4

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@vger.kernel.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Please read the FAQ at  http://www.tux.org/lkml/

Back to linux.kernel | Previous | NextNext in thread | Find similar | Unroll thread


Thread

[PATCH net 3/7] openvswitch: Fix skb leak in ovs_fragment() Joe Stringer <joestringer@nicira.com> - 2015-09-30 00:50 +0200
  Re: [PATCH net 3/7] openvswitch: Fix skb leak in ovs_fragment() "Rustad, Mark D" <mark.d.rustad@intel.com> - 2015-09-30 00:50 +0200
    Re: [PATCH net 3/7] openvswitch: Fix skb leak in ovs_fragment() Joe Stringer <joestringer@nicira.com> - 2015-09-30 01:20 +0200
  Re: [PATCH net 3/7] openvswitch: Fix skb leak in ovs_fragment() Sergei Shtylyov <sergei.shtylyov@cogentembedded.com> - 2015-09-30 16:50 +0200

csiph-web