Skip to content

Commit

Permalink
bridge: fix a possible use after free
Browse files Browse the repository at this point in the history
br_multicast_ipv6_rcv() can call pskb_trim_rcsum() and therefore skb
head can be reallocated.

Cache icmp6_type field instead of dereferencing twice the struct
icmp6hdr pointer.

Signed-off-by: Eric Dumazet <eric.dumazet@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
  • Loading branch information
Eric Dumazet authored and davem330 committed Aug 25, 2011
1 parent 4b275d7 commit 22df133
Showing 1 changed file with 4 additions and 4 deletions.
8 changes: 4 additions & 4 deletions net/bridge/br_multicast.c
Expand Up @@ -1456,7 +1456,7 @@ static int br_multicast_ipv6_rcv(struct net_bridge *br,
{
struct sk_buff *skb2;
const struct ipv6hdr *ip6h;
struct icmp6hdr *icmp6h;
u8 icmp6_type;
u8 nexthdr;
unsigned len;
int offset;
Expand Down Expand Up @@ -1502,9 +1502,9 @@ static int br_multicast_ipv6_rcv(struct net_bridge *br,
__skb_pull(skb2, offset);
skb_reset_transport_header(skb2);

icmp6h = icmp6_hdr(skb2);
icmp6_type = icmp6_hdr(skb2)->icmp6_type;

switch (icmp6h->icmp6_type) {
switch (icmp6_type) {
case ICMPV6_MGM_QUERY:
case ICMPV6_MGM_REPORT:
case ICMPV6_MGM_REDUCTION:
Expand Down Expand Up @@ -1544,7 +1544,7 @@ static int br_multicast_ipv6_rcv(struct net_bridge *br,

BR_INPUT_SKB_CB(skb)->igmp = 1;

switch (icmp6h->icmp6_type) {
switch (icmp6_type) {
case ICMPV6_MGM_REPORT:
{
struct mld_msg *mld;
Expand Down

0 comments on commit 22df133

Please sign in to comment.