]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
bpf: lwt: Fix dst reference leak on reroute failure
authorXuanqiang Luo <luoxuanqiang@kylinos.cn>
Thu, 23 Jul 2026 06:04:45 +0000 (14:04 +0800)
committerPaolo Abeni <pabeni@redhat.com>
Tue, 28 Jul 2026 11:22:11 +0000 (13:22 +0200)
bpf_lwt_xmit_reroute() obtains a referenced dst from the route
lookup. When skb_cow_head() fails before that dst is installed on the
skb, the error path only frees the skb. The skb still owns its previous
dst, so the newly looked up dst reference is leaked.

Release the new dst reference before freeing the skb on this error
path.

Fixes: 3bd0b15281af ("bpf: add handling of BPF_LWT_REROUTE to lwt_bpf.c")
Cc: stable@vger.kernel.org
Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn>
Link: https://patch.msgid.link/20260723060445.21926-1-xuanqiang.luo@linux.dev
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
net/core/lwt_bpf.c

index bf588f508b79e68f8857fc6a9ff30cd2d085bdec..652952d416f238d5e34ae1bf17730f9c6051e789 100644 (file)
@@ -255,8 +255,10 @@ static int bpf_lwt_xmit_reroute(struct sk_buff *skb)
         * if there is enough header space in skb.
         */
        err = skb_cow_head(skb, LL_RESERVED_SPACE(dst->dev));
-       if (unlikely(err))
+       if (unlikely(err)) {
+               dst_release(dst);
                goto err;
+       }
 
        skb_dst_drop(skb);
        skb_dst_set(skb, dst);