mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 17:47:41 +02:00
net: hip04: fix RX buffer leak on build_skb failure
When build_skb() fails in hip04_rx_poll(), the driver jumps to the
refill path without releasing the current RX buffer and its DMA mapping.
Installing a replacement buffer then overwrites the slot references and
leaks both resources.
Keep the current slot intact and return budget so NAPI retries the same
buffer. Also free a newly allocated RX fragment when dma_map_single()
fails.
This issue was found by an in-house static analysis tool.
Fixes: 701a0fd523 ("hip04_eth: fix missing error handle for build_skb failed")
Cc: stable@vger.kernel.org
Signed-off-by: Fan Wu <fanwu01@zju.edu.cn>
Reviewed-by: Jacob Keller <jacob.e.keller@intel.com>
Link: https://patch.msgid.link/20260712142729.2057636-1-fanwu01@zju.edu.cn
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
06ec76fa53
commit
14fa65d10f
|
|
@ -594,7 +594,11 @@ static int hip04_rx_poll(struct napi_struct *napi, int budget)
|
|||
skb = build_skb(buf, priv->rx_buf_size);
|
||||
if (unlikely(!skb)) {
|
||||
net_dbg_ratelimited("build_skb failed\n");
|
||||
goto refill;
|
||||
/* Retain the slot; return budget so NAPI retries this
|
||||
* buffer. Refill would overwrite rx_buf[]/rx_phys[]
|
||||
* and leak them.
|
||||
*/
|
||||
return budget;
|
||||
}
|
||||
|
||||
dma_unmap_single(priv->dev, priv->rx_phys[priv->rx_head],
|
||||
|
|
@ -622,14 +626,15 @@ static int hip04_rx_poll(struct napi_struct *napi, int budget)
|
|||
rx++;
|
||||
}
|
||||
|
||||
refill:
|
||||
buf = netdev_alloc_frag(priv->rx_buf_size);
|
||||
if (!buf)
|
||||
goto done;
|
||||
phys = dma_map_single(priv->dev, buf,
|
||||
RX_BUF_SIZE, DMA_FROM_DEVICE);
|
||||
if (dma_mapping_error(priv->dev, phys))
|
||||
if (dma_mapping_error(priv->dev, phys)) {
|
||||
skb_free_frag(buf);
|
||||
goto done;
|
||||
}
|
||||
priv->rx_buf[priv->rx_head] = buf;
|
||||
priv->rx_phys[priv->rx_head] = phys;
|
||||
hip04_set_recv_desc(priv, phys);
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user