Michal Kubecek caaa7d
From: Eric Dumazet <edumazet@google.com>
Michal Kubecek caaa7d
Date: Tue, 22 Mar 2022 17:41:47 -0700
Michal Kubecek caaa7d
Subject: llc: fix netdevice reference leaks in llc_ui_bind()
Michal Kubecek caaa7d
MIME-Version: 1.0
Michal Kubecek caaa7d
Content-Type: text/plain; charset=UTF-8
Michal Kubecek caaa7d
Content-Transfer-Encoding: 8bit
Michal Kubecek caaa7d
Patch-mainline: v5.18-rc1
Michal Kubecek caaa7d
Git-commit: 764f4eb6846f5475f1244767d24d25dd86528a4a
Michal Kubecek 658b50
References: CVE-2022-28356 bsc#1197391
Michal Kubecek caaa7d
Michal Kubecek caaa7d
Whenever llc_ui_bind() and/or llc_ui_autobind()
Michal Kubecek caaa7d
took a reference on a netdevice but subsequently fail,
Michal Kubecek caaa7d
they must properly release their reference
Michal Kubecek caaa7d
or risk the infamous message from unregister_netdevice()
Michal Kubecek caaa7d
at device dismantle.
Michal Kubecek caaa7d
Michal Kubecek caaa7d
unregister_netdevice: waiting for eth0 to become free. Usage count = 3
Michal Kubecek caaa7d
Michal Kubecek caaa7d
Fixes: 1da177e4c3f4 ("Linux-2.6.12-rc2")
Michal Kubecek caaa7d
Signed-off-by: Eric Dumazet <edumazet@google.com>
Michal Kubecek caaa7d
Reported-by: 赵子轩 <beraphin@gmail.com>
Michal Kubecek caaa7d
Reported-by: Stoyan Manolov <smanolov@suse.de>
Michal Kubecek caaa7d
Link: https://lore.kernel.org/r/20220323004147.1990845-1-eric.dumazet@gmail.com
Michal Kubecek caaa7d
Signed-off-by: Jakub Kicinski <kuba@kernel.org>
Michal Kubecek caaa7d
Acked-by: Michal Kubecek <mkubecek@suse.cz>
Michal Kubecek caaa7d
Michal Kubecek caaa7d
SLE/openSUSE: use dev_put() rather than dev_put_track() which was only
Michal Kubecek caaa7d
introduced in mainline 5.17-rc1.
Michal Kubecek caaa7d
Michal Kubecek caaa7d
---
Michal Kubecek caaa7d
 net/llc/af_llc.c | 8 ++++++++
Michal Kubecek caaa7d
 1 file changed, 8 insertions(+)
Michal Kubecek caaa7d
Michal Kubecek caaa7d
--- a/net/llc/af_llc.c
Michal Kubecek caaa7d
+++ b/net/llc/af_llc.c
Michal Kubecek caaa7d
@@ -299,6 +299,10 @@ static int llc_ui_autobind(struct socket *sock, struct sockaddr_llc *addr)
Michal Kubecek caaa7d
 	sock_reset_flag(sk, SOCK_ZAPPED);
Michal Kubecek caaa7d
 	rc = 0;
Michal Kubecek caaa7d
 out:
Michal Kubecek caaa7d
+	if (rc) {
Michal Kubecek caaa7d
+		dev_put(llc->dev);
Michal Kubecek caaa7d
+		llc->dev = NULL;
Michal Kubecek caaa7d
+	}
Michal Kubecek caaa7d
 	return rc;
Michal Kubecek caaa7d
 }
Michal Kubecek caaa7d
 
Michal Kubecek caaa7d
@@ -398,6 +402,10 @@ static int llc_ui_bind(struct socket *sock, struct sockaddr *uaddr, int addrlen)
Michal Kubecek caaa7d
 out_put:
Michal Kubecek caaa7d
 	llc_sap_put(sap);
Michal Kubecek caaa7d
 out:
Michal Kubecek caaa7d
+	if (rc) {
Michal Kubecek caaa7d
+		dev_put(llc->dev);
Michal Kubecek caaa7d
+		llc->dev = NULL;
Michal Kubecek caaa7d
+	}
Michal Kubecek caaa7d
 	release_sock(sk);
Michal Kubecek caaa7d
 	return rc;
Michal Kubecek caaa7d
 }