mirror of
https://github.com/torvalds/linux.git
synced 2026-07-27 01:32:21 +02:00
llc: fix SAP refcount leak when creating incoming sockets
llc_sap_add_socket() takes a SAP reference for each socket added to a SAP, and llc_sap_remove_socket() releases it. llc_create_incoming_sock() takes an additional SAP reference after adding the child socket. This extra reference was balanced by an explicit llc_sap_put() in llc_ui_release() until commit3100aa9d74("llc: fix SAP reference counting w.r.t. socket handling") removed that put. The corresponding hold in the accept path was left behind. When such a child socket is removed, only the reference taken by llc_sap_add_socket() is released. The extra reference keeps the SAP alive after its last socket is removed. Remove the obsolete hold. Fixes:3100aa9d74("llc: fix SAP reference counting w.r.t. socket handling") Cc: stable@vger.kernel.org Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn> Link: https://patch.msgid.link/20260712130343.518797-1-xuanqiang.luo@linux.dev Signed-off-by: Paolo Abeni <pabeni@redhat.com>
This commit is contained in:
parent
04aeddf2da
commit
2c72eb6286
|
|
@ -767,7 +767,6 @@ static struct sock *llc_create_incoming_sock(struct sock *sk,
|
|||
newllc->dev = dev;
|
||||
dev_hold(dev);
|
||||
llc_sap_add_socket(llc->sap, newsk);
|
||||
llc_sap_hold(llc->sap);
|
||||
out:
|
||||
return newsk;
|
||||
}
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user