[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-Id: <20180807.155439.354237715944692354.davem@davemloft.net>
Date: Tue, 07 Aug 2018 15:54:39 -0700 (PDT)
From: David Miller <davem@...emloft.net>
To: xiyou.wangcong@...il.com
Cc: netdev@...r.kernel.org
Subject: Re: [Patch net] llc: use refcount_inc_not_zero() for llc_sap_find()
From: Cong Wang <xiyou.wangcong@...il.com>
Date: Tue, 7 Aug 2018 12:41:38 -0700
> llc_sap_put() decreases the refcnt before deleting sap
> from the global list. Therefore, there is a chance
> llc_sap_find() could find a sap with zero refcnt
> in this global list.
>
> Close this race condition by checking if refcnt is zero
> or not in llc_sap_find(), if it is zero then it is being
> removed so we can just treat it as gone.
>
> Reported-by: <syzbot+278893f3f7803871f7ce@...kaller.appspotmail.com>
> Signed-off-by: Cong Wang <xiyou.wangcong@...il.com>
Applied and queued up for -stable, thanks.
Powered by blists - more mailing lists