From mboxrd@z Thu Jan 1 00:00:00 1970 From: David Miller Subject: Re: [PATCH net-next] pptp: remove a buggy dst release in pptp_connect() Date: Wed, 04 Apr 2018 11:19:44 -0400 (EDT) Message-ID: <20180404.111944.806737121690699196.davem@davemloft.net> References: <20180403014837.56377-1-edumazet@google.com> Mime-Version: 1.0 Content-Type: Text/Plain; charset=us-ascii Content-Transfer-Encoding: 7bit Cc: netdev@vger.kernel.org, eric.dumazet@gmail.com To: edumazet@google.com Return-path: Received: from shards.monkeyblade.net ([184.105.139.130]:40060 "EHLO shards.monkeyblade.net" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751363AbeDDPTq (ORCPT ); Wed, 4 Apr 2018 11:19:46 -0400 In-Reply-To: <20180403014837.56377-1-edumazet@google.com> Sender: netdev-owner@vger.kernel.org List-ID: From: Eric Dumazet Date: Mon, 2 Apr 2018 18:48:37 -0700 > Once dst has been cached in socket via sk_setup_caps(), > it is illegal to call ip_rt_put() (or dst_release()), > since sk_setup_caps() did not change dst refcount. > > We can still dereference it since we hold socket lock. > > Caugth by syzbot : ... > Signed-off-by: Eric Dumazet Applied and queued up for -stable, thanks Eric.