瀏覽代碼

i40e/i40evf: Fix use after free in Rx cleanup path

We need to reset skb back to NULL when we have freed it in the Rx cleanup
path.  I found one spot where this wasn't occurring so this patch fixes it.

Change-ID: Iaca68934200732cd4a63eb0bd83b539c95f8c4dd
Signed-off-by: Alexander Duyck <alexander.h.duyck@intel.com>
Tested-by: Andrew Bowers <andrewx.bowers@intel.com>
Signed-off-by: Jeff Kirsher <jeffrey.t.kirsher@intel.com>
Alexander Duyck 8 年之前
父節點
當前提交
741b8b832a
共有 2 個文件被更改,包括 2 次插入0 次删除
  1. 1 0
      drivers/net/ethernet/intel/i40e/i40e_txrx.c
  2. 1 0
      drivers/net/ethernet/intel/i40evf/i40e_txrx.c

+ 1 - 0
drivers/net/ethernet/intel/i40e/i40e_txrx.c

@@ -1941,6 +1941,7 @@ static int i40e_clean_rx_irq(struct i40e_ring *rx_ring, int budget)
 		 */
 		 */
 		if (unlikely(i40e_test_staterr(rx_desc, BIT(I40E_RXD_QW1_ERROR_SHIFT)))) {
 		if (unlikely(i40e_test_staterr(rx_desc, BIT(I40E_RXD_QW1_ERROR_SHIFT)))) {
 			dev_kfree_skb_any(skb);
 			dev_kfree_skb_any(skb);
+			skb = NULL;
 			continue;
 			continue;
 		}
 		}
 
 

+ 1 - 0
drivers/net/ethernet/intel/i40evf/i40e_txrx.c

@@ -1299,6 +1299,7 @@ static int i40e_clean_rx_irq(struct i40e_ring *rx_ring, int budget)
 		 */
 		 */
 		if (unlikely(i40e_test_staterr(rx_desc, BIT(I40E_RXD_QW1_ERROR_SHIFT)))) {
 		if (unlikely(i40e_test_staterr(rx_desc, BIT(I40E_RXD_QW1_ERROR_SHIFT)))) {
 			dev_kfree_skb_any(skb);
 			dev_kfree_skb_any(skb);
+			skb = NULL;
 			continue;
 			continue;
 		}
 		}