diff options
| author | Stefano Brivio <sbrivio@redhat.com> | 2019-01-02 07:29:27 -0500 |
|---|---|---|
| committer | David S. Miller <davem@davemloft.net> | 2019-01-02 13:29:20 -0500 |
| commit | 7adf3246092f5e87ed0fa610e8088fae416c581f (patch) | |
| tree | a1f95986879abc9bcc2dfcb296cfe0d64683fd3f /net | |
| parent | 202700e30740c6568b5a6943662f3829566dd533 (diff) | |
ipv6: route: Fix return value of ip6_neigh_lookup() on neigh_create() error
In ip6_neigh_lookup(), we must not return errors coming from
neigh_create(): if creation of a neighbour entry fails, the lookup should
return NULL, in the same way as it's done in __neigh_lookup().
Otherwise, callers legitimately checking for a non-NULL return value of
the lookup function might dereference an invalid pointer.
For instance, on neighbour table overflow, ndisc_router_discovery()
crashes ndisc_update() by passing ERR_PTR(-ENOBUFS) as 'neigh' argument.
Reported-by: Jianlin Shi <jishi@redhat.com>
Fixes: f8a1b43b709d ("net/ipv6: Create a neigh_lookup for FIB entries")
Signed-off-by: Stefano Brivio <sbrivio@redhat.com>
Reviewed-by: David Ahern <dsahern@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net')
| -rw-r--r-- | net/ipv6/route.c | 4 |
1 files changed, 3 insertions, 1 deletions
diff --git a/net/ipv6/route.c b/net/ipv6/route.c index a94e0b02a8ac..40b225f87d5e 100644 --- a/net/ipv6/route.c +++ b/net/ipv6/route.c | |||
| @@ -210,7 +210,9 @@ struct neighbour *ip6_neigh_lookup(const struct in6_addr *gw, | |||
| 210 | n = __ipv6_neigh_lookup(dev, daddr); | 210 | n = __ipv6_neigh_lookup(dev, daddr); |
| 211 | if (n) | 211 | if (n) |
| 212 | return n; | 212 | return n; |
| 213 | return neigh_create(&nd_tbl, daddr, dev); | 213 | |
| 214 | n = neigh_create(&nd_tbl, daddr, dev); | ||
| 215 | return IS_ERR(n) ? NULL : n; | ||
| 214 | } | 216 | } |
| 215 | 217 | ||
| 216 | static struct neighbour *ip6_dst_neigh_lookup(const struct dst_entry *dst, | 218 | static struct neighbour *ip6_dst_neigh_lookup(const struct dst_entry *dst, |
