• Jakub Kicinski's avatar
    net: mpls: fix stale pointer if allocation fails during device rename · fda6c89f
    Jakub Kicinski authored
    lianhui reports that when MPLS fails to register the sysctl table
    under new location (during device rename) the old pointers won't
    get overwritten and may be freed again (double free).
    
    Handle this gracefully. The best option would be unregistering
    the MPLS from the device completely on failure, but unfortunately
    mpls_ifdown() can fail. So failing fully is also unreliable.
    
    Another option is to register the new table first then only
    remove old one if the new one succeeds. That requires more
    code, changes order of notifications and two tables may be
    visible at the same time.
    
    sysctl point is not used in the rest of the code - set to NULL
    on failures and skip unregister if already NULL.
    Reported-by: default avatarlianhui tang <bluetlh@gmail.com>
    Fixes: 0fae3bf0 ("mpls: handle device renames for per-device sysctls")
    Signed-off-by: default avatarJakub Kicinski <kuba@kernel.org>
    Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
    fda6c89f
af_mpls.c 63.6 KB