From: Elad Nachman <enachman@marvell.com>
To: <taras.chornyi@plvision.eu>, <davem@davemloft.net>,
<edumazet@google.com>, <kuba@kernel.org>, <pabeni@redhat.com>,
<andrew@lunn.ch>, <kory.maincent@bootlin.com>,
<thomas.petazzoni@bootlin.com>, <miquel.raynal@bootlin.com>,
<przemyslaw.kitszel@intel.com>, <dkirjanov@suse.de>,
<netdev@vger.kernel.org>, <linux-kernel@vger.kernel.org>
Cc: <enachman@marvell.com>
Subject: [PATCH v2 3/5] net: marvell: prestera: fix memory use after free
Date: Wed, 20 Mar 2024 19:20:06 +0200 [thread overview]
Message-ID: <20240320172008.2989693-4-enachman@marvell.com> (raw)
In-Reply-To: <20240320172008.2989693-1-enachman@marvell.com>
From: Elad Nachman <enachman@marvell.com>
Prestera driver routing module cleanup process would release memory,
then reference it again and eventually free it again the second time.
Remove the redundant first memory free call.
All such double free calls were detected using KASAN.
Fixes: 4394fbcb78cf ("net: marvell: prestera: handle fib notifications")
Signed-off-by: Elad Nachman <enachman@marvell.com>
---
drivers/net/ethernet/marvell/prestera/prestera_router.c | 1 -
drivers/net/ethernet/marvell/prestera/prestera_router_hw.c | 1 -
2 files changed, 2 deletions(-)
diff --git a/drivers/net/ethernet/marvell/prestera/prestera_router.c b/drivers/net/ethernet/marvell/prestera/prestera_router.c
index de317179a7dc..2da04a17efad 100644
--- a/drivers/net/ethernet/marvell/prestera/prestera_router.c
+++ b/drivers/net/ethernet/marvell/prestera/prestera_router.c
@@ -1638,7 +1638,6 @@ void prestera_router_fini(struct prestera_switch *sw)
prestera_k_arb_abort(sw);
kfree(sw->router->nhgrp_hw_state_cache);
- rhashtable_destroy(&sw->router->kern_fib_cache_ht);
prestera_router_hw_fini(sw);
kfree(sw->router);
sw->router = NULL;
diff --git a/drivers/net/ethernet/marvell/prestera/prestera_router_hw.c b/drivers/net/ethernet/marvell/prestera/prestera_router_hw.c
index 02faaea2aefa..254107f664b4 100644
--- a/drivers/net/ethernet/marvell/prestera/prestera_router_hw.c
+++ b/drivers/net/ethernet/marvell/prestera/prestera_router_hw.c
@@ -102,7 +102,6 @@ void prestera_router_hw_fini(struct prestera_switch *sw)
prestera_fib_node_destroy_ht_cb, sw);
WARN_ON(!list_empty(&sw->router->vr_list));
WARN_ON(!list_empty(&sw->router->rif_entry_list));
- rhashtable_destroy(&sw->router->fib_ht);
rhashtable_destroy(&sw->router->nexthop_group_ht);
rhashtable_destroy(&sw->router->nh_neigh_ht);
}
--
2.25.1
next prev parent reply other threads:[~2024-03-20 17:20 UTC|newest]
Thread overview: 24+ messages / expand[flat|nested] mbox.gz Atom feed top
2024-03-20 17:20 [PATCH v2 0/5] Fix prestera driver fail to probe twice Elad Nachman
2024-03-20 17:20 ` [PATCH v2 1/5] net: marvell: prestera: fix driver reload Elad Nachman
2024-03-20 22:58 ` Andrew Lunn
2024-03-21 17:22 ` [EXTERNAL] " Elad Nachman
2024-03-20 17:20 ` [PATCH v2 2/5] net: marvell: prestera: enlarge fw restart time Elad Nachman
2024-03-21 0:10 ` Andrew Lunn
2024-03-21 17:24 ` [EXTERNAL] " Elad Nachman
2024-03-20 17:20 ` Elad Nachman [this message]
2024-03-21 0:14 ` [PATCH v2 3/5] net: marvell: prestera: fix memory use after free Andrew Lunn
2024-03-20 17:20 ` [PATCH v2 4/5] net: marvell: prestera: force good base mac Elad Nachman
2024-03-21 0:13 ` Andrew Lunn
2024-03-20 17:20 ` [PATCH v2 5/5] net: marvell: prestera: unbind sfp port on exit Elad Nachman
2024-03-21 0:13 ` Andrew Lunn
2024-03-21 0:18 ` [PATCH v2 0/5] Fix prestera driver fail to probe twice Andrew Lunn
2024-03-21 17:33 ` [EXTERNAL] " Elad Nachman
2024-03-21 19:22 ` Andrew Lunn
2024-03-24 7:53 ` Elad Nachman
2024-03-24 15:25 ` Andrew Lunn
2024-03-25 12:45 ` Kory Maincent
2024-03-25 13:04 ` Andrew Lunn
2024-03-27 17:27 ` Elad Nachman
2025-03-10 14:08 ` Kory Maincent
2024-03-21 9:06 ` Kory Maincent
2024-03-21 15:53 ` Jakub Kicinski
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20240320172008.2989693-4-enachman@marvell.com \
--to=enachman@marvell.com \
--cc=andrew@lunn.ch \
--cc=davem@davemloft.net \
--cc=dkirjanov@suse.de \
--cc=edumazet@google.com \
--cc=kory.maincent@bootlin.com \
--cc=kuba@kernel.org \
--cc=linux-kernel@vger.kernel.org \
--cc=miquel.raynal@bootlin.com \
--cc=netdev@vger.kernel.org \
--cc=pabeni@redhat.com \
--cc=przemyslaw.kitszel@intel.com \
--cc=taras.chornyi@plvision.eu \
--cc=thomas.petazzoni@bootlin.com \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox