From mboxrd@z Thu Jan 1 00:00:00 1970 From: Eric Dumazet Subject: Re: Possible netfilter-related memory corruption in 2.6.37 Date: Mon, 14 Feb 2011 17:48:48 +0100 Message-ID: <1297702128.2996.41.camel@edumazet-laptop> References: <4D594313.4050009@redhat.com> <1297696283.2996.33.camel@edumazet-laptop> <1297698641.2996.38.camel@edumazet-laptop> <4D595745.7070505@trash.net> <1297700955.2996.40.camel@edumazet-laptop> <4D595A48.9070201@trash.net> Mime-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: QUOTED-PRINTABLE Cc: Jan Engelhardt , Avi Kivity , netfilter-devel@vger.kernel.org, Marcelo Tosatti , nicolas prochazka , KVM list , netdev To: Patrick McHardy Return-path: In-Reply-To: <4D595A48.9070201@trash.net> Sender: netfilter-devel-owner@vger.kernel.org List-Id: netdev.vger.kernel.org Le lundi 14 f=C3=A9vrier 2011 =C3=A0 17:37 +0100, Patrick McHardy a =C3= =A9crit : > Am 14.02.2011 17:29, schrieb Eric Dumazet: > > Le lundi 14 f=C3=A9vrier 2011 =C3=A0 17:24 +0100, Patrick McHardy a= =C3=A9crit : > >>> Also, I wonder if RCU rules are respected in nf_iterate(). > >>> For example this line is really suspicious : > >>> > >>> *i =3D (*i)->prev; > >> > >> Yeah, that definitely looks wrong. How about this instead? > >> > >=20 > > This patch seems fine to me, thanks ! > >=20 > > Acked-by: Eric Dumazet >=20 > THanks Eric, I've queued the patch for 2.6.38. I am not sure, but I guess nf_reinject() needs a fix too ;) -- To unsubscribe from this list: send the line "unsubscribe netfilter-dev= el" in the body of a message to majordomo@vger.kernel.org More majordomo info at http://vger.kernel.org/majordomo-info.html