Skip to content

Commit f44dc80

Browse files
author
Hangbin Liu
committed
ipv6: sr: fix possible use-after-free and null-ptr-deref
JIRA: https://issues.redhat.com/browse/RHEL-30814 JIRA: https://issues.redhat.com/browse/RHEL-31732 Upstream Status: net.git commit 5559cea CVE: CVE-2024-26735 commit 5559cea Author: Vasiliy Kovalev <kovalev@altlinux.org> Date: Thu Feb 15 23:27:17 2024 +0300 ipv6: sr: fix possible use-after-free and null-ptr-deref The pernet operations structure for the subsystem must be registered before registering the generic netlink family. Fixes: 915d7e5 ("ipv6: sr: add code base for control plane support of SR-IPv6") Signed-off-by: Vasiliy Kovalev <kovalev@altlinux.org> Link: https://lore.kernel.org/r/20240215202717.29815-1-kovalev@altlinux.org Signed-off-by: Paolo Abeni <pabeni@redhat.com> Signed-off-by: Hangbin Liu <haliu@redhat.com>
1 parent 4d0ff99 commit f44dc80

File tree

1 file changed

+11
-9
lines changed

1 file changed

+11
-9
lines changed

net/ipv6/seg6.c

Lines changed: 11 additions & 9 deletions
Original file line numberDiff line numberDiff line change
@@ -512,22 +512,24 @@ int __init seg6_init(void)
512512
{
513513
int err;
514514

515-
err = genl_register_family(&seg6_genl_family);
515+
err = register_pernet_subsys(&ip6_segments_ops);
516516
if (err)
517517
goto out;
518518

519-
err = register_pernet_subsys(&ip6_segments_ops);
519+
err = genl_register_family(&seg6_genl_family);
520520
if (err)
521-
goto out_unregister_genl;
521+
goto out_unregister_pernet;
522522

523523
#ifdef CONFIG_IPV6_SEG6_LWTUNNEL
524524
err = seg6_iptunnel_init();
525525
if (err)
526-
goto out_unregister_pernet;
526+
goto out_unregister_genl;
527527

528528
err = seg6_local_init();
529-
if (err)
530-
goto out_unregister_pernet;
529+
if (err) {
530+
seg6_iptunnel_exit();
531+
goto out_unregister_genl;
532+
}
531533
#endif
532534

533535
#ifdef CONFIG_IPV6_SEG6_HMAC
@@ -548,11 +550,11 @@ int __init seg6_init(void)
548550
#endif
549551
#endif
550552
#ifdef CONFIG_IPV6_SEG6_LWTUNNEL
551-
out_unregister_pernet:
552-
unregister_pernet_subsys(&ip6_segments_ops);
553-
#endif
554553
out_unregister_genl:
555554
genl_unregister_family(&seg6_genl_family);
555+
#endif
556+
out_unregister_pernet:
557+
unregister_pernet_subsys(&ip6_segments_ops);
556558
goto out;
557559
}
558560

0 commit comments

Comments
 (0)