]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
net: ipv6: clear suppressed fib6 rule result
authorZhiling Zou <zhilinz@nebusec.ai>
Thu, 23 Jul 2026 16:48:52 +0000 (00:48 +0800)
committerJakub Kicinski <kuba@kernel.org>
Mon, 27 Jul 2026 22:20:01 +0000 (15:20 -0700)
fib6_rule_suppress() drops a suppressed route with ip6_rt_put_flags(),
but leaves res->rt6 pointing at the released rt6_info.

If no later rule supplies a replacement, fib6_rule_lookup() still sees
res.rt6 and returns that stale dst to its caller. A suppressing rule can
therefore leak a released route back to rt6_lookup(), and the next put
hits rcuref_put_slowpath() from dst_release().

Clear res->rt6 when suppressing the route so suppressed lookups fall
through to the null dst instead of reusing the released one.

Fixes: cdef485217d3 ("ipv6: fix memory leak in fib6_rule_suppress")
Cc: stable@vger.kernel.org
Reported-by: Vega <vega@nebusec.ai>
Signed-off-by: Zhiling Zou <zhilinz@nebusec.ai>
Signed-off-by: Ren Wei <enjou1224z@gmail.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Link: https://patch.msgid.link/4b8acb7787d54e440155585dd32ebdf0bef7d122.1784710966.git.zhilinz@nebusec.ai
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/ipv6/fib6_rules.c

index e1b2b4fa6e189027c0d9648537fe166550e0f594..89ee3c969ca75ea4b7ce21c06b4d1843e7dea305 100644 (file)
@@ -308,6 +308,7 @@ INDIRECT_CALLABLE_SCOPE bool fib6_rule_suppress(struct fib_rule *rule,
 
 suppress_route:
        ip6_rt_put_flags(rt, flags);
+       res->rt6 = NULL;
        return true;
 }