From: xiaoshoukui@gmail.com
To: netdev@vger.kernel.org
Cc: edumazet@google.com, w@1wt.eu, jmaloy@redhat.com,
tung.quang.nguyen@dektech.com.au, xiaoshoukui@ruijie.com.cn
Subject: [PATCH net] tipc: fix memory leaks in bundle and fragment paths
Date: Wed, 16 Sep 2026 06:12:20 +0000 [thread overview]
Message-ID: <20260916061220.798324-1-xiaoshoukui@gmail.com> (raw)
From: xiaoshoukui <xiaoshoukui@gmail.com>
tipc_data_input() returns false when an extracted inner skb or
reassembled fragment is not consumed (e.g. unhandled protocol user
types).
The bundle extraction loop and fragment reassembly path in
tipc_link_input() both ignore this return value, leaving unconsumed
skbs unreachable and leaking SLUB memory.
Fix this by freeing unconsumed skbs with kfree_skb_reason() and
setting the drop reason to SKB_DROP_REASON_UNHANDLED_PROTO.
Fixes: c637c1035534 ("tipc: resolve race problem at unicast message reception")
Signed-off-by: xiaoshoukui <xiaoshoukui@gmail.com>
---
net/tipc/link.c | 9 ++++++---
1 file changed, 6 insertions(+), 3 deletions(-)
diff --git a/net/tipc/link.c b/net/tipc/link.c
index 49dfc098d89b..3278a559347b 100644
--- a/net/tipc/link.c
+++ b/net/tipc/link.c
@@ -1306,15 +1306,18 @@ static int tipc_link_input(struct tipc_link *l, struct sk_buff *skb,
skb_queue_head_init(&tmpq);
l->stats.recv_bundles++;
l->stats.recv_bundled += msg_msgcnt(hdr);
- while (tipc_msg_extract(skb, &iskb, &pos))
- tipc_data_input(l, iskb, &tmpq);
+ while (tipc_msg_extract(skb, &iskb, &pos)) {
+ if (!tipc_data_input(l, iskb, &tmpq))
+ kfree_skb_reason(iskb, SKB_DROP_REASON_UNHANDLED_PROTO);
+ }
tipc_skb_queue_splice_tail(&tmpq, inputq);
return 0;
} else if (usr == MSG_FRAGMENTER) {
l->stats.recv_fragments++;
if (tipc_buf_append(reasm_skb, &skb)) {
l->stats.recv_fragmented++;
- tipc_data_input(l, skb, inputq);
+ if (!tipc_data_input(l, skb, inputq))
+ kfree_skb_reason(skb, SKB_DROP_REASON_UNHANDLED_PROTO);
} else if (!*reasm_skb && !link_is_bc_rcvlink(l)) {
pr_warn_ratelimited("Unable to build fragment list\n");
return tipc_link_fsm_evt(l, LINK_FAILURE_EVT);
--
2.34.1
next reply other threads:[~2026-09-16 6:14 UTC|newest]
Thread overview: 5+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-16 6:12 xiaoshoukui [this message]
2026-09-17 3:51 ` [PATCH net] tipc: fix memory leaks in bundle and fragment paths Tung Quang Nguyen
2026-09-21 3:47 ` xiaoshoukui
2026-09-21 9:28 ` Tung Quang Nguyen
2026-09-25 13:43 ` xiaoshoukui
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260916061220.798324-1-xiaoshoukui@gmail.com \
--to=xiaoshoukui@gmail.com \
--cc=edumazet@google.com \
--cc=jmaloy@redhat.com \
--cc=netdev@vger.kernel.org \
--cc=tung.quang.nguyen@dektech.com.au \
--cc=w@1wt.eu \
--cc=xiaoshoukui@ruijie.com.cn \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox