net: ipv6: fix dst refleaks in rpl, seg6 and ioam6 lwtunnels
commitc71a192976upstream. dst_cache_get() gives us a reference, we need to release it. Discovered by the ioam6.sh test, kmemleak was recently fixed to catch per-cpu memory leaks. Fixes:985ec6f5e6("net: ipv6: rpl_iptunnel: mitigate 2-realloc issue") Fixes:40475b6376("net: ipv6: seg6_iptunnel: mitigate 2-realloc issue") Fixes:dce525185b("net: ipv6: ioam6_iptunnel: mitigate 2-realloc issue") Reviewed-by: Justin Iurman <justin.iurman@uliege.be> Reviewed-by: Simon Horman <horms@kernel.org> Link: https://patch.msgid.link/20250130031519.2716843-1-kuba@kernel.org Signed-off-by: Jakub Kicinski <kuba@kernel.org> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
This commit is contained in:
committed by
Greg Kroah-Hartman
parent
02e4373593
commit
bf500b0d0c
@@ -232,7 +232,6 @@ static int rpl_output(struct net *net, struct sock *sk, struct sk_buff *skb)
|
||||
dst = ip6_route_output(net, NULL, &fl6);
|
||||
if (dst->error) {
|
||||
err = dst->error;
|
||||
dst_release(dst);
|
||||
goto drop;
|
||||
}
|
||||
|
||||
@@ -251,6 +250,7 @@ static int rpl_output(struct net *net, struct sock *sk, struct sk_buff *skb)
|
||||
return dst_output(net, sk, skb);
|
||||
|
||||
drop:
|
||||
dst_release(dst);
|
||||
kfree_skb(skb);
|
||||
return err;
|
||||
}
|
||||
@@ -277,8 +277,10 @@ static int rpl_input(struct sk_buff *skb)
|
||||
local_bh_enable();
|
||||
|
||||
err = rpl_do_srh(skb, rlwt, dst);
|
||||
if (unlikely(err))
|
||||
if (unlikely(err)) {
|
||||
dst_release(dst);
|
||||
goto drop;
|
||||
}
|
||||
|
||||
skb_dst_drop(skb);
|
||||
|
||||
|
||||
@@ -490,8 +490,10 @@ static int seg6_input_core(struct net *net, struct sock *sk,
|
||||
local_bh_enable();
|
||||
|
||||
err = seg6_do_srh(skb, dst);
|
||||
if (unlikely(err))
|
||||
if (unlikely(err)) {
|
||||
dst_release(dst);
|
||||
goto drop;
|
||||
}
|
||||
|
||||
skb_dst_drop(skb);
|
||||
|
||||
@@ -582,7 +584,6 @@ static int seg6_output_core(struct net *net, struct sock *sk,
|
||||
dst = ip6_route_output(net, NULL, &fl6);
|
||||
if (dst->error) {
|
||||
err = dst->error;
|
||||
dst_release(dst);
|
||||
goto drop;
|
||||
}
|
||||
|
||||
@@ -604,6 +605,7 @@ static int seg6_output_core(struct net *net, struct sock *sk,
|
||||
|
||||
return dst_output(net, sk, skb);
|
||||
drop:
|
||||
dst_release(dst);
|
||||
kfree_skb(skb);
|
||||
return err;
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user