]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
ipv6: release fib6_null_entry on subtree failure
authorShuangpeng Bai <shuangpeng.kernel@gmail.com>
Mon, 27 Jul 2026 18:53:39 +0000 (14:53 -0400)
committerJakub Kicinski <kuba@kernel.org>
Wed, 29 Jul 2026 23:49:39 +0000 (16:49 -0700)
When adding a source-specific route creates a new subtree, fib6_add()
installs fib6_null_entry as the temporary leaf of the new subtree root
and takes a fib6_info reference for that holder.

If adding the first source leaf fails, the code frees the just allocated
subtree root but leaves that hold behind. fib6_null_entry is a per-netns
sentinel and is freed directly at netns teardown, so this does not keep
the object alive. However, it leaves its visible refcount permanently
elevated and can eventually saturate the refcount on repeated failures.

Drop the null-entry reference before freeing the unlinked subtree root.

Fixes: 5ea715289af6 ("ipv6: broadly use fib6_info_hold() helper")
Signed-off-by: Shuangpeng Bai <shuangpeng.kernel@gmail.com>
Reviewed-by: Ido Schimmel <idosch@nvidia.com>
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Link: https://patch.msgid.link/20260727185339.1545169-1-shuangpeng.kernel@gmail.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
net/ipv6/ip6_fib.c

index a130cdfaebfbee09cd08ad9f6f39259ff639b27b..e9fc692d4f3b22c455333103230cbcf3edfae678 100644 (file)
@@ -1494,6 +1494,7 @@ int fib6_add(struct fib6_node *root, struct fib6_info *rt,
                                   root, and then (in failure) stale node
                                   in main tree.
                                 */
+                               fib6_info_release(info->nl_net->ipv6.fib6_null_entry);
                                node_free_immediate(info->nl_net, sfn);
                                err = PTR_ERR(sn);
                                goto failure;