Eric Dumazet
a0c2dc1fe6
nfc: fix memory leak in llcp_sock_bind()
sysbot reported a memory leak after a bind() has failed.
While we are at it, abort the operation if kmemdup() has failed.
BUG: memory leak
unreferenced object 0xffff888105d83ec0 (size 32):
comm "syz-executor067", pid 7207, jiffies 4294956228 (age 19.430s)
hex dump (first 32 bytes):
00 69 6c 65 20 72 65 61 64 00 6e 65 74 3a 5b 34 .ile read.net:[4
30 32 36 35 33 33 30 39 37 5d 00 00 00 00 00 00 026533097]......
backtrace:
[<0000000036bac473>] kmemleak_alloc_recursive /./include/linux/kmemleak.h:43 [inline]
[<0000000036bac473>] slab_post_alloc_hook /mm/slab.h:522 [inline]
[<0000000036bac473>] slab_alloc /mm/slab.c:3319 [inline]
[<0000000036bac473>] __do_kmalloc /mm/slab.c:3653 [inline]
[<0000000036bac473>] __kmalloc_track_caller+0x169/0x2d0 /mm/slab.c:3670
[<000000000cd39d07>] kmemdup+0x27/0x60 /mm/util.c:120
[<000000008e57e5fc>] kmemdup /./include/linux/string.h:432 [inline]
[<000000008e57e5fc>] llcp_sock_bind+0x1b3/0x230 /net/nfc/llcp_sock.c:107
[<000000009cb0b5d3>] __sys_bind+0x11c/0x140 /net/socket.c:1647
[<00000000492c3bbc>] __do_sys_bind /net/socket.c:1658 [inline]
[<00000000492c3bbc>] __se_sys_bind /net/socket.c:1656 [inline]
[<00000000492c3bbc>] __x64_sys_bind+0x1e/0x30 /net/socket.c:1656
[<0000000008704b2a>] do_syscall_64+0x76/0x1a0 /arch/x86/entry/common.c:296
[<000000009f4c57a4>] entry_SYSCALL_64_after_hwframe+0x44/0xa9
Fixes: 30cc458765 ("NFC: Move LLCP code to the NFC top level diirectory")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: syzbot <syzkaller@googlegroups.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
|
2019-10-04 18:31:36 -07:00 |
| .. |
|
6lowpan
|
|
|
|
9p
|
9p pull request for inclusion in 5.4
|
2019-09-27 15:10:34 -07:00 |
|
802
|
|
|
|
8021q
|
|
|
|
appletalk
|
appletalk: enforce CAP_NET_RAW for raw sockets
|
2019-09-24 16:37:18 +02:00 |
|
atm
|
pppoatm: use %*ph to print small buffer
|
2019-09-05 12:33:28 +02:00 |
|
ax25
|
ax25: enforce CAP_NET_RAW for raw sockets
|
2019-09-24 16:37:18 +02:00 |
|
batman-adv
|
netfilter: drop bridge nf reset from nf_reset
|
2019-10-01 18:42:15 +02:00 |
|
bluetooth
|
Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net-next
|
2019-09-18 12:34:53 -07:00 |
|
bpf
|
|
|
|
bpfilter
|
|
|
|
bridge
|
Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net
|
2019-09-15 14:17:27 +02:00 |
|
caif
|
|
|
|
can
|
can: add support of SAE J1939 protocol
|
2019-09-04 14:22:33 +02:00 |
|
ceph
|
libceph: use ceph_kvmalloc() for osdmap arrays
|
2019-09-16 12:06:25 +02:00 |
|
core
|
net: make sock_prot_memory_pressure() return "const char *"
|
2019-10-04 14:30:23 -07:00 |
|
dcb
|
|
|
|
dccp
|
netfilter: drop bridge nf reset from nf_reset
|
2019-10-01 18:42:15 +02:00 |
|
decnet
|
|
|
|
dns_resolver
|
|
|
|
dsa
|
net: dsa: sja1105: Fix sleeping while atomic in .port_hwtstamp_set
|
2019-10-02 12:19:53 -04:00 |
|
ethernet
|
|
|
|
hsr
|
|
|
|
ieee802154
|
ieee802154: enforce CAP_NET_RAW for raw sockets
|
2019-09-24 16:37:18 +02:00 |
|
ife
|
net: Fix Kconfig indentation
|
2019-09-26 08:56:17 +02:00 |
|
ipv4
|
net: ipv4: avoid mixed n_redirects and rate_tokens usage
|
2019-10-04 17:27:04 -07:00 |
|
ipv6
|
ipv6: Handle missing host route in __ipv6_ifa_notify
|
2019-10-04 18:08:58 -07:00 |
|
iucv
|
|
|
|
kcm
|
kcm: disable preemption in kcm_parse_func_strparser()
|
2019-09-27 10:27:14 +02:00 |
|
key
|
|
|
|
l2tp
|
netfilter: drop bridge nf reset from nf_reset
|
2019-10-01 18:42:15 +02:00 |
|
l3mdev
|
|
|
|
lapb
|
|
|
|
llc
|
|
|
|
mac80211
|
mac80211: keep BHs disabled while calling drv_tx_wake_queue()
|
2019-10-01 17:56:19 +02:00 |
|
mac802154
|
|
|
|
mpls
|
|
|
|
ncsi
|
net/ncsi: Disable global multicast filter
|
2019-09-19 18:04:40 -07:00 |
|
netfilter
|
netfilter: nft_connlimit: disable bh on garbage collection
|
2019-10-01 18:42:15 +02:00 |
|
netlabel
|
netlabel: remove redundant assignment to pointer iter
|
2019-09-01 11:45:02 -07:00 |
|
netlink
|
|
|
|
netrom
|
|
|
|
nfc
|
nfc: fix memory leak in llcp_sock_bind()
|
2019-10-04 18:31:36 -07:00 |
|
nsh
|
|
|
|
openvswitch
|
netfilter: drop bridge nf reset from nf_reset
|
2019-10-01 18:42:15 +02:00 |
|
packet
|
netfilter: drop bridge nf reset from nf_reset
|
2019-10-01 18:42:15 +02:00 |
|
phonet
|
|
|
|
psample
|
net: sched: take reference to psample group in flow_action infra
|
2019-09-16 09:18:03 +02:00 |
|
qrtr
|
net: qrtr: Stop rx_worker before freeing node
|
2019-09-21 18:45:46 -07:00 |
|
rds
|
net/rds: Fix error handling in rds_ib_add_one()
|
2019-10-02 12:16:57 -04:00 |
|
rfkill
|
|
|
|
rose
|
|
|
|
rxrpc
|
Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net
|
2019-09-15 14:17:27 +02:00 |
|
sched
|
sch_dsmark: fix potential NULL deref in dsmark_init()
|
2019-10-04 18:28:30 -07:00 |
|
sctp
|
netfilter: drop bridge nf reset from nf_reset
|
2019-10-01 18:42:15 +02:00 |
|
smc
|
|
|
|
strparser
|
|
|
|
sunrpc
|
Highlights:
|
2019-09-27 17:00:27 -07:00 |
|
switchdev
|
|
|
|
tipc
|
tipc: fix unlimited bundling of small messages
|
2019-10-02 11:02:05 -04:00 |
|
tls
|
net/tls: align non temporal copy to cache lines
|
2019-09-07 18:10:34 +02:00 |
|
unix
|
|
|
|
vmw_vsock
|
vsock: Fix a lockdep warning in __vsock_release()
|
2019-10-01 21:23:35 -04:00 |
|
wimax
|
|
|
|
wireless
|
nl80211: fix null pointer dereference
|
2019-10-01 17:56:19 +02:00 |
|
x25
|
|
|
|
xdp
|
Merge git://git.kernel.org/pub/scm/linux/kernel/git/netdev/net
|
2019-09-28 17:47:33 -07:00 |
|
xfrm
|
netfilter: drop bridge nf reset from nf_reset
|
2019-10-01 18:42:15 +02:00 |
|
compat.c
|
|
|
|
Kconfig
|
|
|
|
Makefile
|
|
|
|
socket.c
|
|
|
|
sysctl_net.c
|
|
|