| From 5b1f0b936010cc6c0017a37e576851cc8318c6bb Mon Sep 17 00:00:00 2001 |
| From: Cong Wang <xiyou.wangcong@gmail.com> |
| Date: Fri, 10 Jan 2020 11:53:08 -0800 |
| Subject: [PATCH] netfilter: fix a use-after-free in mtype_destroy() |
| |
| commit c120959387efa51479056fd01dc90adfba7a590c upstream. |
| |
| map->members is freed by ip_set_free() right before using it in |
| mtype_ext_cleanup() again. So we just have to move it down. |
| |
| Reported-by: syzbot+4c3cc6dbe7259dbf9054@syzkaller.appspotmail.com |
| Fixes: 40cd63bf33b2 ("netfilter: ipset: Support extensions which need a per data destroy function") |
| Acked-by: Jozsef Kadlecsik <kadlec@netfilter.org> |
| Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com> |
| Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org> |
| Signed-off-by: Paul Gortmaker <paul.gortmaker@windriver.com> |
| |
| diff --git a/net/netfilter/ipset/ip_set_bitmap_gen.h b/net/netfilter/ipset/ip_set_bitmap_gen.h |
| index 8acc4e173167..dc9fa0382291 100644 |
| --- a/net/netfilter/ipset/ip_set_bitmap_gen.h |
| +++ b/net/netfilter/ipset/ip_set_bitmap_gen.h |
| @@ -61,9 +61,9 @@ mtype_destroy(struct ip_set *set) |
| if (SET_WITH_TIMEOUT(set)) |
| del_timer_sync(&map->gc); |
| |
| - ip_set_free(map->members); |
| if (set->dsize && set->extensions & IPSET_EXT_DESTROY) |
| mtype_ext_cleanup(set); |
| + ip_set_free(map->members); |
| ip_set_free(map); |
| |
| set->data = NULL; |
| -- |
| 2.7.4 |
| |