From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1756559AbXKKXCh (ORCPT ); Sun, 11 Nov 2007 18:02:37 -0500 Received: (majordomo@vger.kernel.org) by vger.kernel.org id S1752817AbXKKXC1 (ORCPT ); Sun, 11 Nov 2007 18:02:27 -0500 Received: from fk-out-0910.google.com ([209.85.128.184]:61981 "EHLO fk-out-0910.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1752230AbXKKXC0 (ORCPT ); Sun, 11 Nov 2007 18:02:26 -0500 DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=beta; h=received:from:to:subject:date:user-agent:cc:mime-version:content-type:content-transfer-encoding:content-disposition:message-id; b=LGXozSwj786SsLjma48WSZW/AzYq1x8C+MxYGugIouCqY6EDNtXdD70C74+uEidpj9MNpC2oiGu3VH+CGAv5DTVjGiPcEfBV5+iRi2RiBKXxhR0nt+ccglIWX3uMXOdHEZf9mdsJEzLqNWphOXCPbF5IpzcLu3+tykhv7AL9ryU= From: Jesper Juhl To: lksctp developers Subject: [PATCH] Fix memory leak in discard case of sctp_sf_abort_violation() Date: Sun, 11 Nov 2007 23:57:49 +0100 User-Agent: KMail/1.9.7 Cc: netdev@vger.kernel.org, Linux Kernel Mailing List , Vlad Yasevich , Sridhar Samudrala , Jesper Juhl MIME-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Content-Disposition: inline Message-Id: <200711112357.49577.jesper.juhl@gmail.com> Sender: linux-kernel-owner@vger.kernel.org X-Mailing-List: linux-kernel@vger.kernel.org From: Jesper Juhl In net/sctp/sm_statefuns.c::sctp_sf_abort_violation() we may leak the storage allocated for 'abort' by returning from the function without using or freeing it. This happens in case "sctp_auth_recv_cid(SCTP_CID_ABORT, asoc)" is true and we jump to the 'discard' label. Spotted by the Coverity checker. The simple fix is to simply move the creation of the "abort chunk" to after the possible jump to the 'discard' label. This way we don't even have to allocate the memory at all in the problem case. Signed-off-by: Jesper Juhl --- sm_statefuns.c | 10 +++++----- 1 file changed, 5 insertions(+), 5 deletions(-) diff --git a/net/sctp/sm_statefuns.c b/net/sctp/sm_statefuns.c index f01b408..4c5c5e7 100644 --- a/net/sctp/sm_statefuns.c +++ b/net/sctp/sm_statefuns.c @@ -4064,11 +4064,6 @@ static sctp_disposition_t sctp_sf_abort_violation( struct sctp_chunk *chunk = arg; struct sctp_chunk *abort = NULL; - /* Make the abort chunk. */ - abort = sctp_make_abort_violation(asoc, chunk, payload, paylen); - if (!abort) - goto nomem; - /* SCTP-AUTH, Section 6.3: * It should be noted that if the receiver wants to tear * down an association in an authenticated way only, the @@ -4083,6 +4078,11 @@ static sctp_disposition_t sctp_sf_abort_violation( if (sctp_auth_recv_cid(SCTP_CID_ABORT, asoc)) goto discard; + /* Make the abort chunk. */ + abort = sctp_make_abort_violation(asoc, chunk, payload, paylen); + if (!abort) + goto nomem; + if (asoc) { sctp_add_cmd_sf(commands, SCTP_CMD_REPLY, SCTP_CHUNK(abort)); SCTP_INC_STATS(SCTP_MIB_OUTCTRLCHUNKS);