]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
net: hip04: fix RX buffer leak on build_skb failure
authorFan Wu <fanwu01@zju.edu.cn>
Sun, 12 Jul 2026 14:27:29 +0000 (14:27 +0000)
committerJakub Kicinski <kuba@kernel.org>
Wed, 22 Jul 2026 15:04:19 +0000 (08:04 -0700)
When build_skb() fails in hip04_rx_poll(), the driver jumps to the
refill path without releasing the current RX buffer and its DMA mapping.
Installing a replacement buffer then overwrites the slot references and
leaks both resources.

Keep the current slot intact and return budget so NAPI retries the same
buffer.  Also free a newly allocated RX fragment when dma_map_single()
fails.

This issue was found by an in-house static analysis tool.

Fixes: 701a0fd52318 ("hip04_eth: fix missing error handle for build_skb failed")
Cc: stable@vger.kernel.org
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Reviewed-by: Jacob Keller <jacob.e.keller@intel.com>
Link: https://patch.msgid.link/20260712142729.2057636-1-fanwu01@zju.edu.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
drivers/net/ethernet/hisilicon/hip04_eth.c

index 18376bcc718a2075de84b661bc7fd3015dbfa1ff..fc2c47dcfaabeaaee1034671832157e66327a990 100644 (file)
@@ -594,7 +594,11 @@ static int hip04_rx_poll(struct napi_struct *napi, int budget)
                skb = build_skb(buf, priv->rx_buf_size);
                if (unlikely(!skb)) {
                        net_dbg_ratelimited("build_skb failed\n");
-                       goto refill;
+                       /* Retain the slot; return budget so NAPI retries this
+                        * buffer. Refill would overwrite rx_buf[]/rx_phys[]
+                        * and leak them.
+                        */
+                       return budget;
                }
 
                dma_unmap_single(priv->dev, priv->rx_phys[priv->rx_head],
@@ -622,14 +626,15 @@ static int hip04_rx_poll(struct napi_struct *napi, int budget)
                        rx++;
                }
 
-refill:
                buf = netdev_alloc_frag(priv->rx_buf_size);
                if (!buf)
                        goto done;
                phys = dma_map_single(priv->dev, buf,
                                      RX_BUF_SIZE, DMA_FROM_DEVICE);
-               if (dma_mapping_error(priv->dev, phys))
+               if (dma_mapping_error(priv->dev, phys)) {
+                       skb_free_frag(buf);
                        goto done;
+               }
                priv->rx_buf[priv->rx_head] = buf;
                priv->rx_phys[priv->rx_head] = phys;
                hip04_set_recv_desc(priv, phys);