Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > linux.kernel > #1347451 > unrolled thread

[PATCH 4.4 033/342] tcp: md5: release request socket instead of listener

Started byGreg Kroah-Hartman <gregkh@linuxfoundation.org>
First post2016-03-02 02:20 +0100
Last post2016-03-02 02:20 +0100
Articles 1 — 1 participant

Back to article view | Back to linux.kernel

This discussion starts older than the indexed window; earlier articles aren't shown. The article labeled Started by below is the oldest one visible, not the original post.


Contents

  [PATCH 4.4 033/342] tcp: md5: release request socket instead of listener Greg Kroah-Hartman <gregkh@linuxfoundation.org> - 2016-03-02 02:20 +0100

#1347451 — [PATCH 4.4 033/342] tcp: md5: release request socket instead of listener

FromGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Date2016-03-02 02:20 +0100
Subject[PATCH 4.4 033/342] tcp: md5: release request socket instead of listener
Message-ID<r83Ck-jE-63@gated-at.bofh.it>
4.4-stable review patch.  If anyone has any objections, please let me know.

------------------

From: Eric Dumazet <edumazet@google.com>

[ Upstream commit 729235554d805c63e5e274fcc6a98e71015dd847 ]

If tcp_v4_inbound_md5_hash() returns an error, we must release
the refcount on the request socket, not on the listener.

The bug was added for IPv4 only.

Fixes: 079096f103fac ("tcp/dccp: install syn_recv requests into ehash table")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
---
 net/ipv4/tcp_ipv4.c |    6 ++++--
 1 file changed, 4 insertions(+), 2 deletions(-)

--- a/net/ipv4/tcp_ipv4.c
+++ b/net/ipv4/tcp_ipv4.c
@@ -1597,8 +1597,10 @@ process:
 		struct sock *nsk = NULL;
 
 		sk = req->rsk_listener;
-		if (tcp_v4_inbound_md5_hash(sk, skb))
-			goto discard_and_relse;
+		if (unlikely(tcp_v4_inbound_md5_hash(sk, skb))) {
+			reqsk_put(req);
+			goto discard_it;
+		}
 		if (likely(sk->sk_state == TCP_LISTEN)) {
 			nsk = tcp_check_req(sk, skb, req, false);
 		} else {

[toc] | [standalone]


Back to top | Article view | linux.kernel


csiph-web