diff options
author | Jeff Hansen <x@jeffhansen.com> | 2009-09-28 12:54:25 -0700 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2009-09-28 12:54:25 -0700 |
commit | 30df94f800368a016d09ee672c9fcc20751d0260 (patch) | |
tree | 1626c98991a1c828d6d359100f5db5bb4e20a946 /net/bridge/br_if.c | |
parent | 8823ad31cd3baf73bd21913cf030b9e7afd22923 (diff) | |
download | op-kernel-dev-30df94f800368a016d09ee672c9fcc20751d0260.zip op-kernel-dev-30df94f800368a016d09ee672c9fcc20751d0260.tar.gz |
bridge: Fix double-free in br_add_if.
There is a potential double-kfree in net/bridge/br_if.c. If br_fdb_insert
fails, then the kobject is put back (which calls kfree due to the kobject
release), and then kfree is called again on the net_bridge_port. This
patch fixes the crash.
Thanks to Stephen Hemminger for the one-line fix.
Signed-off-by: Jeff Hansen <x@jeffhansen.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/bridge/br_if.c')
-rw-r--r-- | net/bridge/br_if.c | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/net/bridge/br_if.c b/net/bridge/br_if.c index 142ebac..b1b3b0f 100644 --- a/net/bridge/br_if.c +++ b/net/bridge/br_if.c @@ -432,6 +432,7 @@ err2: br_fdb_delete_by_port(br, p, 1); err1: kobject_put(&p->kobj); + p = NULL; /* kobject_put frees */ err0: dev_set_promiscuity(dev, -1); put_back: |