diff options
author | Eric Dumazet <eric.dumazet@gmail.com> | 2010-05-28 01:09:39 +0200 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2010-05-28 10:57:16 +0200 |
commit | a47311380e094bb201be8a818370c73c3f52122c (patch) | |
tree | da4eb4607fece39b9cdb03fb69792e44a914d2bd | |
parent | vhost: fix the memory leak which will happen when memory_access_ok fails (diff) | |
download | linux-a47311380e094bb201be8a818370c73c3f52122c.tar.xz linux-a47311380e094bb201be8a818370c73c3f52122c.zip |
net: fix __neigh_event_send()
commit 7fee226ad23 (net: add a noref bit on skb dst) missed one spot
where an skb is enqueued, with a possibly not refcounted dst entry.
__neigh_event_send() inserts skb into arp_queue, so we must make sure
dst entry is refcounted, or dst entry can be freed by garbage collector
after caller exits from rcu protected section.
Reported-by: Ingo Molnar <mingo@elte.hu>
Tested-by: Ingo Molnar <mingo@elte.hu>
Signed-off-by: Eric Dumazet <eric.dumazet@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
-rw-r--r-- | net/core/neighbour.c | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/net/core/neighbour.c b/net/core/neighbour.c index bff37908bd55..6ba1c0eece03 100644 --- a/net/core/neighbour.c +++ b/net/core/neighbour.c @@ -934,6 +934,7 @@ int __neigh_event_send(struct neighbour *neigh, struct sk_buff *skb) kfree_skb(buff); NEIGH_CACHE_STAT_INC(neigh->tbl, unres_discards); } + skb_dst_force(skb); __skb_queue_tail(&neigh->arp_queue, skb); } rc = 1; |