netdev.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [patch -next] 6LoWPAN: double free in lowpan_fragment_xmit()
@ 2011-11-16  8:21 Dan Carpenter
  2011-11-16  8:32 ` Dan Carpenter
  0 siblings, 1 reply; 5+ messages in thread
From: Dan Carpenter @ 2011-11-16  8:21 UTC (permalink / raw)
  To: Dmitry Eremin-Solenikov, Alexander Smirnov
  Cc: Sergey Lapin, David S. Miller, linux-zigbee-devel, netdev,
	kernel-janitors

dev_queue_xmit() consumes its own skb, so the call to dev_kfree_skb()
ieee802154/6lowpan.clowpan_fragment_xmits a double free.

Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>

diff --git a/net/ieee802154/6lowpan.c b/net/ieee802154/6lowpan.c
index 602f318..e4ecc1e 100644
--- a/net/ieee802154/6lowpan.c
+++ b/net/ieee802154/6lowpan.c
@@ -980,9 +980,6 @@ lowpan_fragment_xmit(struct sk_buff *skb, u8 *head,
 
 	ret = dev_queue_xmit(frag);
 
-	if (ret < 0)
-		dev_kfree_skb(frag);
-
 	return ret;
 }
 

^ permalink raw reply related	[flat|nested] 5+ messages in thread

* Re: [patch -next] 6LoWPAN: double free in lowpan_fragment_xmit()
  2011-11-16  8:21 [patch -next] 6LoWPAN: double free in lowpan_fragment_xmit() Dan Carpenter
@ 2011-11-16  8:32 ` Dan Carpenter
  2011-11-16  8:36   ` [patch -next v2] " Dan Carpenter
  0 siblings, 1 reply; 5+ messages in thread
From: Dan Carpenter @ 2011-11-16  8:32 UTC (permalink / raw)
  To: Dmitry Eremin-Solenikov, Alexander Smirnov
  Cc: Sergey Lapin, David S. Miller, linux-zigbee-devel, netdev,
	kernel-janitors

[-- Attachment #1: Type: text/plain, Size: 339 bytes --]

On Wed, Nov 16, 2011 at 11:21:38AM +0300, Dan Carpenter wrote:
> dev_queue_xmit() consumes its own skb, so the call to dev_kfree_skb()
> ieee802154/6lowpan.clowpan_fragment_xmits a double free.
  ^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^

Dur...  I messed up my commit message right before sending.  Will
resend.

regards,
dan carpenter



[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 836 bytes --]

^ permalink raw reply	[flat|nested] 5+ messages in thread

* [patch -next v2] 6LoWPAN: double free in lowpan_fragment_xmit()
  2011-11-16  8:32 ` Dan Carpenter
@ 2011-11-16  8:36   ` Dan Carpenter
  2011-11-16  8:42     ` Alexander Smirnov
  0 siblings, 1 reply; 5+ messages in thread
From: Dan Carpenter @ 2011-11-16  8:36 UTC (permalink / raw)
  To: Dmitry Eremin-Solenikov, Alexander Smirnov
  Cc: Sergey Lapin, David S. Miller, linux-zigbee-devel, netdev,
	kernel-janitors

[-- Attachment #1: Type: text/plain, Size: 548 bytes --]

dev_queue_xmit() consumes its own skb, so the call to dev_kfree_skb()
in lowpan_fragment_xmit() is a double free.

Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
---
v2: fixed commit message.

diff --git a/net/ieee802154/6lowpan.c b/net/ieee802154/6lowpan.c
index 602f318..e4ecc1e 100644
--- a/net/ieee802154/6lowpan.c
+++ b/net/ieee802154/6lowpan.c
@@ -980,9 +980,6 @@ lowpan_fragment_xmit(struct sk_buff *skb, u8 *head,
 
 	ret = dev_queue_xmit(frag);
 
-	if (ret < 0)
-		dev_kfree_skb(frag);
-
 	return ret;
 }
 


[-- Attachment #2: Digital signature --]
[-- Type: application/pgp-signature, Size: 836 bytes --]

^ permalink raw reply related	[flat|nested] 5+ messages in thread

* Re: [patch -next v2] 6LoWPAN: double free in lowpan_fragment_xmit()
  2011-11-16  8:36   ` [patch -next v2] " Dan Carpenter
@ 2011-11-16  8:42     ` Alexander Smirnov
  2011-11-16 23:14       ` David Miller
  0 siblings, 1 reply; 5+ messages in thread
From: Alexander Smirnov @ 2011-11-16  8:42 UTC (permalink / raw)
  To: Dan Carpenter
  Cc: Dmitry Eremin-Solenikov, Sergey Lapin, David S. Miller,
	linux-zigbee-devel, netdev, kernel-janitors

2011/11/16 Dan Carpenter <dan.carpenter@oracle.com>:
> dev_queue_xmit() consumes its own skb, so the call to dev_kfree_skb()
> in lowpan_fragment_xmit() is a double free.
>
> Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
> ---
> v2: fixed commit message.
>
> diff --git a/net/ieee802154/6lowpan.c b/net/ieee802154/6lowpan.c
> index 602f318..e4ecc1e 100644
> --- a/net/ieee802154/6lowpan.c
> +++ b/net/ieee802154/6lowpan.c
> @@ -980,9 +980,6 @@ lowpan_fragment_xmit(struct sk_buff *skb, u8 *head,
>
>        ret = dev_queue_xmit(frag);
>
> -       if (ret < 0)
> -               dev_kfree_skb(frag);
> -
>        return ret;
>  }
>
>
>

Acked-by: Alexander Smirnov <alex.bluesman.smirnov@gmail.com>

^ permalink raw reply	[flat|nested] 5+ messages in thread

* Re: [patch -next v2] 6LoWPAN: double free in lowpan_fragment_xmit()
  2011-11-16  8:42     ` Alexander Smirnov
@ 2011-11-16 23:14       ` David Miller
  0 siblings, 0 replies; 5+ messages in thread
From: David Miller @ 2011-11-16 23:14 UTC (permalink / raw)
  To: alex.bluesman.smirnov
  Cc: dan.carpenter, dbaryshkov, slapin, linux-zigbee-devel, netdev,
	kernel-janitors

From: Alexander Smirnov <alex.bluesman.smirnov@gmail.com>
Date: Wed, 16 Nov 2011 11:42:07 +0300

> 2011/11/16 Dan Carpenter <dan.carpenter@oracle.com>:
>> dev_queue_xmit() consumes its own skb, so the call to dev_kfree_skb()
>> in lowpan_fragment_xmit() is a double free.
>>
>> Signed-off-by: Dan Carpenter <dan.carpenter@oracle.com>
 ...
> 
> Acked-by: Alexander Smirnov <alex.bluesman.smirnov@gmail.com>

Applied, thanks.

^ permalink raw reply	[flat|nested] 5+ messages in thread

end of thread, other threads:[~2011-11-16 23:14 UTC | newest]

Thread overview: 5+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2011-11-16  8:21 [patch -next] 6LoWPAN: double free in lowpan_fragment_xmit() Dan Carpenter
2011-11-16  8:32 ` Dan Carpenter
2011-11-16  8:36   ` [patch -next v2] " Dan Carpenter
2011-11-16  8:42     ` Alexander Smirnov
2011-11-16 23:14       ` David Miller

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).