From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from mail.linuxfoundation.org ([140.211.169.12]:53045 "EHLO mail.linuxfoundation.org" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1751332AbbEHL5K (ORCPT ); Fri, 8 May 2015 07:57:10 -0400 Subject: Patch "[PATCH] ipv4: Missing sk_nulls_node_init() in ping_unhash()." has been added to the 3.10-stable tree To: davem@davemloft.net, gregkh@linuxfoundation.org, hotdog3645@gmail.com, torvalds@linux-foundation.org Cc: , From: Date: Fri, 08 May 2015 13:57:06 +0200 Message-ID: <1431086226121111@kroah.com> MIME-Version: 1.0 Content-Type: text/plain; charset=ANSI_X3.4-1968 Content-Transfer-Encoding: 8bit Sender: stable-owner@vger.kernel.org List-ID: This is a note to let you know that I've just added the patch titled [PATCH] ipv4: Missing sk_nulls_node_init() in ping_unhash(). to the 3.10-stable tree which can be found at: http://www.kernel.org/git/?p=linux/kernel/git/stable/stable-queue.git;a=summary The filename of the patch is: ipv4-missing-sk_nulls_node_init-in-ping_unhash.patch and it can be found in the queue-3.10 subdirectory. If you, or anyone else, feels it should not be added to the stable tree, please let know about it. >>From foo@baz Fri May 8 13:15:43 CEST 2015 From: "David S. Miller" Date: Fri, 1 May 2015 22:02:47 -0400 Subject: [PATCH] ipv4: Missing sk_nulls_node_init() in ping_unhash(). From: "David S. Miller" [ Upstream commit a134f083e79fb4c3d0a925691e732c56911b4326 ] If we don't do that, then the poison value is left in the ->pprev backlink. This can cause crashes if we do a disconnect, followed by a connect(). Tested-by: Linus Torvalds Reported-by: Wen Xu Signed-off-by: David S. Miller Signed-off-by: Greg Kroah-Hartman --- net/ipv4/ping.c | 1 + 1 file changed, 1 insertion(+) --- a/net/ipv4/ping.c +++ b/net/ipv4/ping.c @@ -139,6 +139,7 @@ static void ping_v4_unhash(struct sock * if (sk_hashed(sk)) { write_lock_bh(&ping_table.lock); hlist_nulls_del(&sk->sk_nulls_node); + sk_nulls_node_init(&sk->sk_nulls_node); sock_put(sk); isk->inet_num = 0; isk->inet_sport = 0; Patches currently in stable-queue which might be from davem@davemloft.net are queue-3.10/ipv4-missing-sk_nulls_node_init-in-ping_unhash.patch