]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
virtio_net: fix memory leak inside XPD_TX with mergeable
authorXuan Zhuo <xuanzhuo@linux.alibaba.com>
Thu, 4 Aug 2022 06:32:48 +0000 (14:32 +0800)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Thu, 25 Aug 2022 09:37:57 +0000 (11:37 +0200)
commit 7a542bee27c6a57e45c33cbbdc963325fd6493af upstream.

When we call xdp_convert_buff_to_frame() to get xdpf, if it returns
NULL, we should check if xdp_page was allocated by xdp_linearize_page().
If it is newly allocated, it should be freed here alone. Just like any
other "goto err_xdp".

Fixes: 44fa2dbd4759 ("xdp: transition into using xdp_frame for ndo_xdp_xmit")
Signed-off-by: Xuan Zhuo <xuanzhuo@linux.alibaba.com>
Acked-by: Jason Wang <jasowang@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
drivers/net/virtio_net.c

index 0a07c05a610d1adb55bf0ddd0b13e778ba426383..c942cd6a2c65ee30ced8991e11d5d8729a7eec6a 100644 (file)
@@ -968,8 +968,11 @@ static struct sk_buff *receive_mergeable(struct net_device *dev,
                case XDP_TX:
                        stats->xdp_tx++;
                        xdpf = xdp_convert_buff_to_frame(&xdp);
-                       if (unlikely(!xdpf))
+                       if (unlikely(!xdpf)) {
+                               if (unlikely(xdp_page != page))
+                                       put_page(xdp_page);
                                goto err_xdp;
+                       }
                        err = virtnet_xdp_xmit(dev, 1, &xdpf, 0);
                        if (unlikely(err < 0)) {
                                trace_xdp_exception(vi->dev, xdp_prog, act);