From mboxrd@z Thu Jan 1 00:00:00 1970 From: Mathieu Xhonneux Subject: [PATCH] bpf: fix mem leak in error path of lwt bpf setup Date: Sun, 20 May 2018 14:08:57 +0100 Message-ID: <20180520130857.1278-1-m.xhonneux@gmail.com> Cc: daniel@iogearbox.net, alexei.starovoitov@gmail.com To: netdev@vger.kernel.org Return-path: Received: from mail-wm0-f67.google.com ([74.125.82.67]:36330 "EHLO mail-wm0-f67.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1750895AbeETLJG (ORCPT ); Sun, 20 May 2018 07:09:06 -0400 Received: by mail-wm0-f67.google.com with SMTP id n10-v6so21989218wmc.1 for ; Sun, 20 May 2018 04:09:05 -0700 (PDT) Sender: netdev-owner@vger.kernel.org List-ID: In bpf_parse_prog, if bpf_prog_get_type fails, the function is immediately terminated without freeing the previously allocated prog->name. This patch adds a kfree before the return. Signed-off-by: Mathieu Xhonneux --- net/core/lwt_bpf.c | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/net/core/lwt_bpf.c b/net/core/lwt_bpf.c index e7e626fb87bb..e142a7a32e46 100644 --- a/net/core/lwt_bpf.c +++ b/net/core/lwt_bpf.c @@ -223,8 +223,10 @@ static int bpf_parse_prog(struct nlattr *attr, struct bpf_lwt_prog *prog, fd = nla_get_u32(tb[LWT_BPF_PROG_FD]); p = bpf_prog_get_type(fd, type); - if (IS_ERR(p)) + if (IS_ERR(p)) { + kfree(prog->name); return PTR_ERR(p); + } prog->prog = p; -- 2.16.1