[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <f68629b9-62f9-5a58-9d5f-f33cb4912bf4@huawei.com>
Date: Thu, 17 Nov 2022 20:14:51 +0800
From: Zhang Changzhong <zhangchangzhong@...wei.com>
To: Leon Romanovsky <leon@...nel.org>
CC: <GR-Linux-NIC-Dev@...vell.com>,
"David S. Miller" <davem@...emloft.net>,
Eric Dumazet <edumazet@...gle.com>,
Jakub Kicinski <kuba@...nel.org>,
"Paolo Abeni" <pabeni@...hat.com>, Jeff Garzik <jeff@...zik.org>,
Ron Mercer <ron.mercer@...gic.com>, <netdev@...r.kernel.org>,
<linux-kernel@...r.kernel.org>
Subject: Re: [PATCH net] net/qla3xxx: fix potential memleak in ql3xxx_send()
On 2022/11/17 19:38, Leon Romanovsky wrote:
> On Thu, Nov 17, 2022 at 04:50:38PM +0800, Zhang Changzhong wrote:
>> The ql3xxx_send() returns NETDEV_TX_OK without freeing skb in error
>> handling case, add dev_kfree_skb_any() to fix it.
>
> Can you please remind me why should it release?
> There are no paths in ql3xxx_send() that release skb.
>
> Thanks
>
If ql_send_map() returns NETDEV_TX_OK, the packet is sent, and
ql_process_mac_tx_intr() releases tx_cb->skb. However, the skb
cannot be released in this error path.
Thanks,
Changzhong
>>
>> Fixes: bd36b0ac5d06 ("qla3xxx: Add support for Qlogic 4032 chip.")
>> Signed-off-by: Zhang Changzhong <zhangchangzhong@...wei.com>
>> ---
>> drivers/net/ethernet/qlogic/qla3xxx.c | 1 +
>> 1 file changed, 1 insertion(+)
>>
>> diff --git a/drivers/net/ethernet/qlogic/qla3xxx.c b/drivers/net/ethernet/qlogic/qla3xxx.c
>> index 76072f8..0d57ffc 100644
>> --- a/drivers/net/ethernet/qlogic/qla3xxx.c
>> +++ b/drivers/net/ethernet/qlogic/qla3xxx.c
>> @@ -2471,6 +2471,7 @@ static netdev_tx_t ql3xxx_send(struct sk_buff *skb,
>> skb_shinfo(skb)->nr_frags);
>> if (tx_cb->seg_count == -1) {
>> netdev_err(ndev, "%s: invalid segment count!\n", __func__);
>> + dev_kfree_skb_any(skb);
>> return NETDEV_TX_OK;
>> }
>>
>> --
>> 2.9.5
>>
> .
>
Powered by blists - more mailing lists