]> git.baikalelectronics.ru Git - kernel.git/commit
xfrm: xfrm_policy: fix a possible double xfrm_pols_put() in xfrm_bundle_lookup()
authorHangyu Hua <hbh25y@gmail.com>
Wed, 1 Jun 2022 06:46:25 +0000 (14:46 +0800)
committerSteffen Klassert <steffen.klassert@secunet.com>
Thu, 2 Jun 2022 09:05:19 +0000 (11:05 +0200)
commitfccb122737d254862cf2e4b15a7e95816adaf224
tree57ff2df72148d7d98119d5a828cd18a7c371fb4a
parent80defba3701bf9501588c89b48bfb17ef059a3e5
xfrm: xfrm_policy: fix a possible double xfrm_pols_put() in xfrm_bundle_lookup()

xfrm_policy_lookup() will call xfrm_pol_hold_rcu() to get a refcount of
pols[0]. This refcount can be dropped in xfrm_expand_policies() when
xfrm_expand_policies() return error. pols[0]'s refcount is balanced in
here. But xfrm_bundle_lookup() will also call xfrm_pols_put() with
num_pols == 1 to drop this refcount when xfrm_expand_policies() return
error.

This patch also fix an illegal address access. pols[0] will save a error
point when xfrm_policy_lookup fails. This lead to xfrm_pols_put to resolve
an illegal address in xfrm_bundle_lookup's error path.

Fix these by setting num_pols = 0 in xfrm_expand_policies()'s error path.

Fixes: bceb06bc1841 ("xfrm: cache bundles instead of policies for outgoing flows")
Signed-off-by: Hangyu Hua <hbh25y@gmail.com>
Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
net/xfrm/xfrm_policy.c