]> git.ipfire.org Git - thirdparty/kernel/stable-queue.git/commitdiff
4.19-stable patches
authorGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 29 Mar 2019 06:08:35 +0000 (07:08 +0100)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 29 Mar 2019 06:08:35 +0000 (07:08 +0100)
added patches:
tun-add-a-missing-rcu_read_unlock-in-error-path.patch

queue-4.19/series
queue-4.19/tun-add-a-missing-rcu_read_unlock-in-error-path.patch [new file with mode: 0644]

index 050d98bb43daad0aa87997c9f9e7644657d4db1b..ff6530a0eb8162f8af74440a319a1f9da493b66c 100644 (file)
@@ -30,3 +30,4 @@ ila-fix-rhashtable-walker-list-corruption.patch
 net-sched-fix-cleanup-null-pointer-exception-in-act_mirr.patch
 thunderx-enable-page-recycling-for-non-xdp-case.patch
 thunderx-eliminate-extra-calls-to-put_page-for-pages-held-for-recycling.patch
+tun-add-a-missing-rcu_read_unlock-in-error-path.patch
diff --git a/queue-4.19/tun-add-a-missing-rcu_read_unlock-in-error-path.patch b/queue-4.19/tun-add-a-missing-rcu_read_unlock-in-error-path.patch
new file mode 100644 (file)
index 0000000..d9c10d2
--- /dev/null
@@ -0,0 +1,32 @@
+From 9180bb4f046064dfa4541488102703b402bb04e1 Mon Sep 17 00:00:00 2001
+From: Eric Dumazet <edumazet@google.com>
+Date: Sat, 16 Mar 2019 13:09:53 -0700
+Subject: tun: add a missing rcu_read_unlock() in error path
+
+From: Eric Dumazet <edumazet@google.com>
+
+commit 9180bb4f046064dfa4541488102703b402bb04e1 upstream.
+
+In my latest patch I missed one rcu_read_unlock(), in case
+device is down.
+
+Fixes: 4477138fa0ae ("tun: properly test for IFF_UP")
+Signed-off-by: Eric Dumazet <edumazet@google.com>
+Reported-by: syzbot <syzkaller@googlegroups.com>
+Signed-off-by: David S. Miller <davem@davemloft.net>
+Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
+
+---
+ drivers/net/tun.c |    1 +
+ 1 file changed, 1 insertion(+)
+
+--- a/drivers/net/tun.c
++++ b/drivers/net/tun.c
+@@ -1915,6 +1915,7 @@ drop:
+       rcu_read_lock();
+       if (unlikely(!(tun->dev->flags & IFF_UP))) {
+               err = -EIO;
++              rcu_read_unlock();
+               goto drop;
+       }