diff options
author | Herbert Xu <herbert@gondor.apana.org.au> | 2009-01-13 22:17:51 -0800 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2009-01-13 22:17:51 -0800 |
commit | 7891cc818967e186be68caac32d84bfd0a3f0bd2 (patch) | |
tree | e8ac3bb46c043f7fd2a39d80e0b61ff7db30fb5c | |
parent | 33966dd0e2f68f26943cd9ee93ec6abbc6547a8e (diff) | |
download | op-kernel-dev-7891cc818967e186be68caac32d84bfd0a3f0bd2.zip op-kernel-dev-7891cc818967e186be68caac32d84bfd0a3f0bd2.tar.gz |
ipv6: Fix fib6_dump_table walker leak
When a fib6 table dump is prematurely ended, we won't unlink
its walker from the list. This causes all sorts of grief for
other users of the list later.
Reported-by: Chris Caputo <ccaputo@alt.net>
Signed-off-by: Herbert Xu <herbert@gondor.apana.org.au>
Signed-off-by: David S. Miller <davem@davemloft.net>
-rw-r--r-- | net/ipv6/ip6_fib.c | 15 |
1 files changed, 8 insertions, 7 deletions
diff --git a/net/ipv6/ip6_fib.c b/net/ipv6/ip6_fib.c index 29c7c99..52ee1dc 100644 --- a/net/ipv6/ip6_fib.c +++ b/net/ipv6/ip6_fib.c @@ -298,6 +298,10 @@ static void fib6_dump_end(struct netlink_callback *cb) struct fib6_walker_t *w = (void*)cb->args[2]; if (w) { + if (cb->args[4]) { + cb->args[4] = 0; + fib6_walker_unlink(w); + } cb->args[2] = 0; kfree(w); } @@ -330,15 +334,12 @@ static int fib6_dump_table(struct fib6_table *table, struct sk_buff *skb, read_lock_bh(&table->tb6_lock); res = fib6_walk_continue(w); read_unlock_bh(&table->tb6_lock); - if (res != 0) { - if (res < 0) - fib6_walker_unlink(w); - goto end; + if (res <= 0) { + fib6_walker_unlink(w); + cb->args[4] = 0; } - fib6_walker_unlink(w); - cb->args[4] = 0; } -end: + return res; } |