From: Eric Dumazet Date: Sun, 29 Apr 2012 09:08:22 +0000 (+0000) Subject: netem: fix possible skb leak X-Git-Tag: v2.6.34.15~163 X-Git-Url: http://git.ipfire.org/cgi-bin/gitweb.cgi?a=commitdiff_plain;h=0c4b80040717fd36afa06186ff676b6a831aa009;p=thirdparty%2Fkernel%2Fstable.git netem: fix possible skb leak commit 116a0fc31c6c9b8fc821be5a96e5bf0b43260131 upstream. skb_checksum_help(skb) can return an error, we must free skb in this case. qdisc_drop(skb, sch) can also be feeded with a NULL skb (if skb_unshare() failed), so lets use this generic helper. Signed-off-by: Eric Dumazet Cc: Stephen Hemminger Signed-off-by: David S. Miller Signed-off-by: Paul Gortmaker --- diff --git a/net/sched/sch_netem.c b/net/sched/sch_netem.c index 4714ff162bbd2..e105245dac93e 100644 --- a/net/sched/sch_netem.c +++ b/net/sched/sch_netem.c @@ -202,10 +202,8 @@ static int netem_enqueue(struct sk_buff *skb, struct Qdisc *sch) if (q->corrupt && q->corrupt >= get_crandom(&q->corrupt_cor)) { if (!(skb = skb_unshare(skb, GFP_ATOMIC)) || (skb->ip_summed == CHECKSUM_PARTIAL && - skb_checksum_help(skb))) { - sch->qstats.drops++; - return NET_XMIT_DROP; - } + skb_checksum_help(skb))) + return qdisc_drop(skb, sch); skb->data[net_random() % skb_headlen(skb)] ^= 1<<(net_random() % 8); }