Skip to content

Commit 112decb

Browse files
committed
net: sched: Fix use after free in red_enqueue()
jira VULN-66497 cve CVE-2022-49921 commit-author Dan Carpenter <[email protected]> commit 8bdc2ac We can't use "skb" again after passing it to qdisc_enqueue(). This is basically identical to commit 2f09707 ("sch_sfb: Also store skb len before calling child enqueue"). Fixes: d7f4f33 ("sch_red: update backlog as well") Signed-off-by: Dan Carpenter <[email protected]> Reviewed-by: Eric Dumazet <[email protected]> Signed-off-by: David S. Miller <[email protected]> (cherry picked from commit 8bdc2ac) Signed-off-by: Anmol Jain <[email protected]>
1 parent c2ec993 commit 112decb

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

net/sched/sch_red.c

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -76,6 +76,7 @@ static int red_enqueue(struct sk_buff *skb, struct Qdisc *sch,
7676
{
7777
struct red_sched_data *q = qdisc_priv(sch);
7878
struct Qdisc *child = q->qdisc;
79+
unsigned int len;
7980
int ret;
8081

8182
q->vars.qavg = red_calc_qavg(&q->parms,
@@ -130,9 +131,10 @@ static int red_enqueue(struct sk_buff *skb, struct Qdisc *sch,
130131
break;
131132
}
132133

134+
len = qdisc_pkt_len(skb);
133135
ret = qdisc_enqueue(skb, child, to_free);
134136
if (likely(ret == NET_XMIT_SUCCESS)) {
135-
qdisc_qstats_backlog_inc(sch, skb);
137+
sch->qstats.backlog += len;
136138
sch->q.qlen++;
137139
} else if (net_xmit_drop_count(ret)) {
138140
q->stats.pdrop++;

0 commit comments

Comments
 (0)