aboutsummaryrefslogtreecommitdiffstats
path: root/net/netrom
diff options
context:
space:
mode:
authorHerbert Xu <herbert@gondor.apana.org.au>2015-07-13 16:04:13 +0800
committerBen Hutchings <ben@decadent.org.uk>2015-10-13 03:46:02 +0100
commit72e6f0680249f5e0a87f2b282d033baefd90d84e (patch)
tree24c0cb8870d7201538c741c9d7112817e61b28b4 /net/netrom
parent931a9653b9dd309f0dcdfaceff259316e5515e72 (diff)
downloadkernel_samsung_smdk4412-72e6f0680249f5e0a87f2b282d033baefd90d84e.zip
kernel_samsung_smdk4412-72e6f0680249f5e0a87f2b282d033baefd90d84e.tar.gz
kernel_samsung_smdk4412-72e6f0680249f5e0a87f2b282d033baefd90d84e.tar.bz2
net: Clone skb before setting peeked flag
commit 738ac1ebb96d02e0d23bc320302a6ea94c612dec upstream. Shared skbs must not be modified and this is crucial for broadcast and/or multicast paths where we use it as an optimisation to avoid unnecessary cloning. The function skb_recv_datagram breaks this rule by setting peeked without cloning the skb first. This causes funky races which leads to double-free. This patch fixes this by cloning the skb and replacing the skb in the list when setting skb->peeked. Fixes: a59322be07c9 ("[UDP]: Only increment counter on first peek/recv") Reported-by: Konstantin Khlebnikov <khlebnikov@yandex-team.ru> Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au> Signed-off-by: David S. Miller <davem@davemloft.net> [bwh: Backported to 3.2: adjust context] Signed-off-by: Ben Hutchings <ben@decadent.org.uk>
Diffstat (limited to 'net/netrom')
0 files changed, 0 insertions, 0 deletions