mirror of
https://github.com/torvalds/linux.git
synced 2026-09-23 05:04:02 +02:00
rtase: fix double free of multi-frag skb on DMA map failure
In rtase_start_xmit(), when the head buffer DMA mapping fails after
rtase_xmit_frags() has mapped all fragments, the error path clears
the fragment descriptors with rtase_tx_clear_range(), which frees
the skb through the last-frag slot and accounts tx_dropped. Control
then falls through to the common error label, which frees the same
skb a second time and counts it again.
Return right after clearing the fragments when the skb owns frags;
the no-frag case still drops through and frees the head skb once.
Fixes: d6e882b89f ("rtase: Implement .ndo_start_xmit function")
Signed-off-by: Yun Lu <luyun@kylinos.cn>
Reviewed-by: Jacob Keller <jacob.e.keller@intel.com>
Reviewed-by: Justin Lai <justinlai0215@realtek.com>
Link: https://patch.msgid.link/20260721023836.6691-1-luyun_611@163.com
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
parent
d211028bac
commit
6fb7b769d6
|
|
@ -1623,6 +1623,9 @@ static netdev_tx_t rtase_start_xmit(struct sk_buff *skb,
|
|||
err_dma_1:
|
||||
ring->skbuff[entry] = NULL;
|
||||
rtase_tx_clear_range(ring, ring->cur_idx + 1, frags);
|
||||
if (frags)
|
||||
/* the frags were cleared above, along with the skb */
|
||||
return NETDEV_TX_OK;
|
||||
|
||||
err_dma_0:
|
||||
tp->stats.tx_dropped++;
|
||||
|
|
|
|||
Loading…
Reference in New Issue
Block a user