Skip to content

Commit 4ec89c5

Browse files
author
Hangbin Liu
committed
ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw().
JIRA: https://issues.redhat.com/browse/RHEL-84573 Upstream Status: net.git commit 9740890 CVE: CVE-2025-22005 commit 9740890 Author: Kuniyuki Iwashima <kuniyu@amazon.com> Date: Tue Mar 11 18:03:25 2025 -0700 ipv6: Fix memleak of nhc_pcpu_rth_output in fib_check_nh_v6_gw(). fib_check_nh_v6_gw() expects that fib6_nh_init() cleans up everything when it fails. Commit 7dd7316 ("ipv6: Always allocate pcpu memory in a fib6_nh") moved fib_nh_common_init() before alloc_percpu_gfp() within fib6_nh_init() but forgot to add cleanup for fib6_nh->nh_common.nhc_pcpu_rth_output in case it fails to allocate fib6_nh->rt6i_pcpu, resulting in memleak. Let's call fib_nh_common_release() and clear nhc_pcpu_rth_output in the error path. Note that we can remove the fib6_nh_release() call in nh_create_ipv6() later in net-next.git. Fixes: 7dd7316 ("ipv6: Always allocate pcpu memory in a fib6_nh") Signed-off-by: Kuniyuki Iwashima <kuniyu@amazon.com> Link: https://patch.msgid.link/20250312010333.56001-1-kuniyu@amazon.com Signed-off-by: Paolo Abeni <pabeni@redhat.com> Signed-off-by: Hangbin Liu <haliu@redhat.com>
1 parent 29c6735 commit 4ec89c5

File tree

1 file changed

+2
-1
lines changed

1 file changed

+2
-1
lines changed

net/ipv6/route.c

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -3650,7 +3650,8 @@ int fib6_nh_init(struct net *net, struct fib6_nh *fib6_nh,
36503650
in6_dev_put(idev);
36513651

36523652
if (err) {
3653-
lwtstate_put(fib6_nh->fib_nh_lws);
3653+
fib_nh_common_release(&fib6_nh->nh_common);
3654+
fib6_nh->nh_common.nhc_pcpu_rth_output = NULL;
36543655
fib6_nh->fib_nh_lws = NULL;
36553656
netdev_put(dev, dev_tracker);
36563657
}

0 commit comments

Comments
 (0)