| From d821864061c6b6f2b656488e2239b6414c837cae Mon Sep 17 00:00:00 2001 |
| From: Sasha Levin <sashal@kernel.org> |
| Date: Mon, 27 May 2019 16:56:48 -0700 |
| Subject: inet: frags: call inet_frags_fini() after unregister_pernet_subsys() |
| |
| From: Eric Dumazet <edumazet@google.com> |
| |
| [ Upstream commit ae7352d384a552d8c799c242e74a934809990a71 ] |
| |
| Both IPv6 and 6lowpan are calling inet_frags_fini() too soon. |
| |
| inet_frags_fini() is dismantling a kmem_cache, that might be needed |
| later when unregister_pernet_subsys() eventually has to remove |
| frags queues from hash tables and free them. |
| |
| This fixes potential use-after-free, and is a prereq for the following patch. |
| |
| Fixes: d4ad4d22e7ac ("inet: frags: use kmem_cache for inet_frag_queue") |
| Signed-off-by: Eric Dumazet <edumazet@google.com> |
| Signed-off-by: David S. Miller <davem@davemloft.net> |
| Signed-off-by: Sasha Levin <sashal@kernel.org> |
| --- |
| net/ieee802154/6lowpan/reassembly.c | 2 +- |
| net/ipv6/reassembly.c | 2 +- |
| 2 files changed, 2 insertions(+), 2 deletions(-) |
| |
| diff --git a/net/ieee802154/6lowpan/reassembly.c b/net/ieee802154/6lowpan/reassembly.c |
| index c01df341b5f64..5936bfafb1c43 100644 |
| --- a/net/ieee802154/6lowpan/reassembly.c |
| +++ b/net/ieee802154/6lowpan/reassembly.c |
| @@ -633,7 +633,7 @@ err_sysctl: |
| |
| void lowpan_net_frag_exit(void) |
| { |
| - inet_frags_fini(&lowpan_frags); |
| lowpan_frags_sysctl_unregister(); |
| unregister_pernet_subsys(&lowpan_frags_ops); |
| + inet_frags_fini(&lowpan_frags); |
| } |
| diff --git a/net/ipv6/reassembly.c b/net/ipv6/reassembly.c |
| index 4aed9c45a91ad..3f488555999e3 100644 |
| --- a/net/ipv6/reassembly.c |
| +++ b/net/ipv6/reassembly.c |
| @@ -592,8 +592,8 @@ err_protocol: |
| |
| void ipv6_frag_exit(void) |
| { |
| - inet_frags_fini(&ip6_frags); |
| ip6_frags_sysctl_unregister(); |
| unregister_pernet_subsys(&ip6_frags_ops); |
| inet6_del_protocol(&frag_protocol, IPPROTO_FRAGMENT); |
| + inet_frags_fini(&ip6_frags); |
| } |
| -- |
| 2.20.1 |
| |