Skip to content

Commit a8c6950

Browse files
dmantipovmarckleinebudde
authored andcommitted
can: j1939: j1939_session_new(): fix skb reference counting
Since j1939_session_skb_queue() does an extra skb_get() for each new skb, do the same for the initial one in j1939_session_new() to avoid refcount underflow. Reported-by: syzbot+d4e8dc385d9258220c31@syzkaller.appspotmail.com Closes: https://syzkaller.appspot.com/bug?extid=d4e8dc385d9258220c31 Fixes: 9d71dd0 ("can: add support of SAE J1939 protocol") Signed-off-by: Dmitry Antipov <dmantipov@yandex.ru> Tested-by: Oleksij Rempel <o.rempel@pengutronix.de> Acked-by: Oleksij Rempel <o.rempel@pengutronix.de> Link: https://patch.msgid.link/20241105094823.2403806-1-dmantipov@yandex.ru [mkl: clean up commit message] Signed-off-by: Marc Kleine-Budde <mkl@pengutronix.de>
1 parent 30447a1 commit a8c6950

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

net/can/j1939/transport.c

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1505,7 +1505,7 @@ static struct j1939_session *j1939_session_new(struct j1939_priv *priv,
15051505
session->state = J1939_SESSION_NEW;
15061506

15071507
skb_queue_head_init(&session->skb_queue);
1508-
skb_queue_tail(&session->skb_queue, skb);
1508+
skb_queue_tail(&session->skb_queue, skb_get(skb));
15091509

15101510
skcb = j1939_skb_to_cb(skb);
15111511
memcpy(&session->skcb, skcb, sizeof(session->skcb));

0 commit comments

Comments
 (0)