net/smc/smc_ib.c | 19 ++++++++++++------- 1 file changed, 12 insertions(+), 7 deletions(-)
In smc_ib_find_route(), the neighbour found by neigh_lookup() and rtable
resolved by ip_route_output_flow() are not released or put before return.
It may cause the refcount leak, so fix it.
Link: https://lore.kernel.org/r/20240506015439.108739-1-guwen@linux.alibaba.com
Fixes: e5c4744cfb59 ("net/smc: add SMC-Rv2 connection establishment")
Signed-off-by: Wen Gu <guwen@linux.alibaba.com>
---
v2->v1
- call ip_rt_put() to release rt as well.
---
net/smc/smc_ib.c | 19 ++++++++++++-------
1 file changed, 12 insertions(+), 7 deletions(-)
diff --git a/net/smc/smc_ib.c b/net/smc/smc_ib.c
index 97704a9e84c7..9297dc20bfe2 100644
--- a/net/smc/smc_ib.c
+++ b/net/smc/smc_ib.c
@@ -209,13 +209,18 @@ int smc_ib_find_route(struct net *net, __be32 saddr, __be32 daddr,
if (IS_ERR(rt))
goto out;
if (rt->rt_uses_gateway && rt->rt_gw_family != AF_INET)
- goto out;
- neigh = rt->dst.ops->neigh_lookup(&rt->dst, NULL, &fl4.daddr);
- if (neigh) {
- memcpy(nexthop_mac, neigh->ha, ETH_ALEN);
- *uses_gateway = rt->rt_uses_gateway;
- return 0;
- }
+ goto out_rt;
+ neigh = dst_neigh_lookup(&rt->dst, &fl4.daddr);
+ if (!neigh)
+ goto out_rt;
+ memcpy(nexthop_mac, neigh->ha, ETH_ALEN);
+ *uses_gateway = rt->rt_uses_gateway;
+ neigh_release(neigh);
+ ip_rt_put(rt);
+ return 0;
+
+out_rt:
+ ip_rt_put(rt);
out:
return -ENOENT;
}
--
2.32.0.3.g01195cf9f
On 07.05.24 14:53, Wen Gu wrote: > In smc_ib_find_route(), the neighbour found by neigh_lookup() and rtable > resolved by ip_route_output_flow() are not released or put before return. > It may cause the refcount leak, so fix it. > > Link: https://lore.kernel.org/r/20240506015439.108739-1-guwen@linux.alibaba.com > Fixes: e5c4744cfb59 ("net/smc: add SMC-Rv2 connection establishment") > Signed-off-by: Wen Gu <guwen@linux.alibaba.com> > --- > v2->v1 > - call ip_rt_put() to release rt as well. > --- > net/smc/smc_ib.c | 19 ++++++++++++------- > 1 file changed, 12 insertions(+), 7 deletions(-) > > diff --git a/net/smc/smc_ib.c b/net/smc/smc_ib.c > index 97704a9e84c7..9297dc20bfe2 100644 > --- a/net/smc/smc_ib.c > +++ b/net/smc/smc_ib.c > @@ -209,13 +209,18 @@ int smc_ib_find_route(struct net *net, __be32 saddr, __be32 daddr, > if (IS_ERR(rt)) > goto out; > if (rt->rt_uses_gateway && rt->rt_gw_family != AF_INET) > - goto out; > - neigh = rt->dst.ops->neigh_lookup(&rt->dst, NULL, &fl4.daddr); > - if (neigh) { > - memcpy(nexthop_mac, neigh->ha, ETH_ALEN); > - *uses_gateway = rt->rt_uses_gateway; > - return 0; > - } > + goto out_rt; > + neigh = dst_neigh_lookup(&rt->dst, &fl4.daddr); > + if (!neigh) > + goto out_rt; > + memcpy(nexthop_mac, neigh->ha, ETH_ALEN); > + *uses_gateway = rt->rt_uses_gateway; > + neigh_release(neigh); > + ip_rt_put(rt); > + return 0; > + > +out_rt: > + ip_rt_put(rt); > out: > return -ENOENT; > } Thank you for fixing it! Reviewed-and-tested-by: Wenjia Zhang <wenjia@linux.ibm.com>
© 2016 - 2024 Red Hat, Inc.