net: avoid NULL deref in inet_ctl_sock_destroy()
authorEric Dumazet <edumazet@google.com>
Fri, 2 Oct 2015 23:54:31 +0000 (16:54 -0700)
committerJiri Slaby <jslaby@suse.cz>
Sat, 14 Nov 2015 16:04:51 +0000 (17:04 +0100)
[ Upstream commit 8fa677d2706d325d71dab91bf6e6512c05214e37 ]

Under low memory conditions, tcp_sk_init() and icmp_sk_init()
can both iterate on all possible cpus and call inet_ctl_sock_destroy(),
with eventual NULL pointer.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Signed-off-by: Jiri Slaby <jslaby@suse.cz>
include/net/inet_common.h

index 234008782c8cca00e2af6394c17391189abd974a..102fc42c7fb11966592c6e5b9ad922f083690557 100644 (file)
@@ -40,7 +40,8 @@ extern int inet_ctl_sock_create(struct sock **sk, unsigned short family,
 
 static inline void inet_ctl_sock_destroy(struct sock *sk)
 {
-       sk_release_kernel(sk);
+       if (sk)
+               sk_release_kernel(sk);
 }
 
 #endif