All of lore.kernel.org
 help / color / mirror / Atom feed
From: Steffen Klassert <steffen.klassert@secunet.com>
To: David Miller <davem@davemloft.net>, Jakub Kicinski <kuba@kernel.org>
Cc: Herbert Xu <herbert@gondor.apana.org.au>,
	Steffen Klassert <steffen.klassert@secunet.com>,
	<netdev@vger.kernel.org>
Subject: [PATCH 1/6] xfrm: fix refcount leak in __xfrm_policy_check()
Date: Wed, 24 Aug 2022 07:02:08 +0200	[thread overview]
Message-ID: <20220824050213.3643599-2-steffen.klassert@secunet.com> (raw)
In-Reply-To: <20220824050213.3643599-1-steffen.klassert@secunet.com>

From: Xin Xiong <xiongx18@fudan.edu.cn>

The issue happens on an error path in __xfrm_policy_check(). When the
fetching process of the object `pols[1]` fails, the function simply
returns 0, forgetting to decrement the reference count of `pols[0]`,
which is incremented earlier by either xfrm_sk_policy_lookup() or
xfrm_policy_lookup(). This may result in memory leaks.

Fix it by decreasing the reference count of `pols[0]` in that path.

Fixes: 134b0fc544ba ("IPsec: propagate security module errors up from flow_cache_lookup")
Signed-off-by: Xin Xiong <xiongx18@fudan.edu.cn>
Signed-off-by: Xin Tan <tanxin.ctf@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
---
 net/xfrm/xfrm_policy.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/net/xfrm/xfrm_policy.c b/net/xfrm/xfrm_policy.c
index f1a0bab920a5..4f8bbb825abc 100644
--- a/net/xfrm/xfrm_policy.c
+++ b/net/xfrm/xfrm_policy.c
@@ -3599,6 +3599,7 @@ int __xfrm_policy_check(struct sock *sk, int dir, struct sk_buff *skb,
 		if (pols[1]) {
 			if (IS_ERR(pols[1])) {
 				XFRM_INC_STATS(net, LINUX_MIB_XFRMINPOLERROR);
+				xfrm_pol_put(pols[0]);
 				return 0;
 			}
 			pols[1]->curlft.use_time = ktime_get_real_seconds();
-- 
2.25.1


  reply	other threads:[~2022-08-24  5:02 UTC|newest]

Thread overview: 8+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2022-08-24  5:02 [PATCH 0/6] pull request (net): ipsec 2022-08-24 Steffen Klassert
2022-08-24  5:02 ` Steffen Klassert [this message]
2022-08-24 12:10   ` [PATCH 1/6] xfrm: fix refcount leak in __xfrm_policy_check() patchwork-bot+netdevbpf
2022-08-24  5:02 ` [PATCH 2/6] Revert "xfrm: update SA curlft.use_time" Steffen Klassert
2022-08-24  5:02 ` [PATCH 3/6] xfrm: fix XFRMA_LASTUSED comment Steffen Klassert
2022-08-24  5:02 ` [PATCH 4/6] xfrm: clone missing x->lastused in xfrm_do_migrate Steffen Klassert
2022-08-24  5:02 ` [PATCH 5/6] af_key: Do not call xfrm_probe_algs in parallel Steffen Klassert
2022-08-24  5:02 ` [PATCH 6/6] xfrm: policy: fix metadata dst->dev xmit null pointer dereference Steffen Klassert

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20220824050213.3643599-2-steffen.klassert@secunet.com \
    --to=steffen.klassert@secunet.com \
    --cc=davem@davemloft.net \
    --cc=herbert@gondor.apana.org.au \
    --cc=kuba@kernel.org \
    --cc=netdev@vger.kernel.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.