]> git.ipfire.org Git - thirdparty/kernel/stable.git/commitdiff
tipc: fix memory leak in tipc_link_xmit
authorTung Nguyen <tung.quang.nguyen@est.tech>
Thu, 3 Apr 2025 09:24:31 +0000 (09:24 +0000)
committerGreg Kroah-Hartman <gregkh@linuxfoundation.org>
Fri, 2 May 2025 05:40:46 +0000 (07:40 +0200)
[ Upstream commit 69ae94725f4fc9e75219d2d69022029c5b24bc9a ]

In case the backlog transmit queue for system-importance messages is overloaded,
tipc_link_xmit() returns -ENOBUFS but the skb list is not purged. This leads to
memory leak and failure when a skb is allocated.

This commit fixes this issue by purging the skb list before tipc_link_xmit()
returns.

Fixes: 365ad353c256 ("tipc: reduce risk of user starvation during link congestion")
Signed-off-by: Tung Nguyen <tung.quang.nguyen@est.tech>
Link: https://patch.msgid.link/20250403092431.514063-1-tung.quang.nguyen@est.tech
Signed-off-by: Paolo Abeni <pabeni@redhat.com>
Signed-off-by: Sasha Levin <sashal@kernel.org>
net/tipc/link.c

index 5f849c730028304405d37f0d97f6a8c0adc88650..336d1bb2cf6a3fe6aac4d5afe2a9a422e178a64b 100644 (file)
@@ -1033,6 +1033,7 @@ int tipc_link_xmit(struct tipc_link *l, struct sk_buff_head *list,
        if (unlikely(l->backlog[imp].len >= l->backlog[imp].limit)) {
                if (imp == TIPC_SYSTEM_IMPORTANCE) {
                        pr_warn("%s<%s>, link overflow", link_rst_msg, l->name);
+                       __skb_queue_purge(list);
                        return -ENOBUFS;
                }
                rc = link_schedule_user(l, hdr);