* [PATCH] Fix memory leak in discard case of sctp_sf_abort_violation()
@ 2007-11-11 22:57 Jesper Juhl
2007-11-12 15:14 ` [Lksctp-developers] " Vlad Yasevich
0 siblings, 1 reply; 2+ messages in thread
From: Jesper Juhl @ 2007-11-11 22:57 UTC (permalink / raw)
To: lksctp developers
Cc: netdev, Linux Kernel Mailing List, Vlad Yasevich,
Sridhar Samudrala, Jesper Juhl
From: Jesper Juhl <jesper.juhl@gmail.com>
In net/sctp/sm_statefuns.c::sctp_sf_abort_violation() we may leak
the storage allocated for 'abort' by returning from the function
without using or freeing it. This happens in case
"sctp_auth_recv_cid(SCTP_CID_ABORT, asoc)" is true and we jump to
the 'discard' label.
Spotted by the Coverity checker.
The simple fix is to simply move the creation of the "abort chunk"
to after the possible jump to the 'discard' label. This way we don't
even have to allocate the memory at all in the problem case.
Signed-off-by: Jesper Juhl <jesper.juhl@gmail.com>
---
sm_statefuns.c | 10 +++++-----
1 file changed, 5 insertions(+), 5 deletions(-)
diff --git a/net/sctp/sm_statefuns.c b/net/sctp/sm_statefuns.c
index f01b408..4c5c5e7 100644
--- a/net/sctp/sm_statefuns.c
+++ b/net/sctp/sm_statefuns.c
@@ -4064,11 +4064,6 @@ static sctp_disposition_t sctp_sf_abort_violation(
struct sctp_chunk *chunk = arg;
struct sctp_chunk *abort = NULL;
- /* Make the abort chunk. */
- abort = sctp_make_abort_violation(asoc, chunk, payload, paylen);
- if (!abort)
- goto nomem;
-
/* SCTP-AUTH, Section 6.3:
* It should be noted that if the receiver wants to tear
* down an association in an authenticated way only, the
@@ -4083,6 +4078,11 @@ static sctp_disposition_t sctp_sf_abort_violation(
if (sctp_auth_recv_cid(SCTP_CID_ABORT, asoc))
goto discard;
+ /* Make the abort chunk. */
+ abort = sctp_make_abort_violation(asoc, chunk, payload, paylen);
+ if (!abort)
+ goto nomem;
+
if (asoc) {
sctp_add_cmd_sf(commands, SCTP_CMD_REPLY, SCTP_CHUNK(abort));
SCTP_INC_STATS(SCTP_MIB_OUTCTRLCHUNKS);
^ permalink raw reply related [flat|nested] 2+ messages in thread
* Re: [Lksctp-developers] [PATCH] Fix memory leak in discard case of sctp_sf_abort_violation()
2007-11-11 22:57 [PATCH] Fix memory leak in discard case of sctp_sf_abort_violation() Jesper Juhl
@ 2007-11-12 15:14 ` Vlad Yasevich
0 siblings, 0 replies; 2+ messages in thread
From: Vlad Yasevich @ 2007-11-12 15:14 UTC (permalink / raw)
To: Jesper Juhl
Cc: lksctp developers, netdev, Linux Kernel Mailing List,
Sridhar Samudrala
Jesper Juhl wrote:
> From: Jesper Juhl <jesper.juhl@gmail.com>
>
> In net/sctp/sm_statefuns.c::sctp_sf_abort_violation() we may leak
> the storage allocated for 'abort' by returning from the function
> without using or freeing it. This happens in case
> "sctp_auth_recv_cid(SCTP_CID_ABORT, asoc)" is true and we jump to
> the 'discard' label.
> Spotted by the Coverity checker.
>
> The simple fix is to simply move the creation of the "abort chunk"
> to after the possible jump to the 'discard' label. This way we don't
> even have to allocate the memory at all in the problem case.
>
>
> Signed-off-by: Jesper Juhl <jesper.juhl@gmail.com>
Thanks. I've applied this to my tree.
-vlad
^ permalink raw reply [flat|nested] 2+ messages in thread
end of thread, other threads:[~2007-11-12 15:14 UTC | newest]
Thread overview: 2+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2007-11-11 22:57 [PATCH] Fix memory leak in discard case of sctp_sf_abort_violation() Jesper Juhl
2007-11-12 15:14 ` [Lksctp-developers] " Vlad Yasevich
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).