diff options
author | Denis V. Lunev <den@openvz.org> | 2008-02-18 20:49:36 -0800 |
---|---|---|
committer | David S. Miller <davem@davemloft.net> | 2008-02-18 20:49:36 -0800 |
commit | 9937ded8e44de8865cba1509d24eea9d350cebf0 (patch) | |
tree | 76cdeafd3acd6f06005b48abbdd7f2c9771f9a92 /net/ipv6/ip6_tunnel.c | |
parent | 8ac62dc773c149d7b7124b4912b425842f905d3e (diff) |
[IPV6]: dst_entry leak in ip4ip6_err. (resend)
The result of the ip_route_output is not assigned to skb. This means that
- it is leaked
- possible OOPS below dereferrencing skb->dst
- no ICMP message for this case
Signed-off-by: Denis V. Lunev <den@openvz.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/ipv6/ip6_tunnel.c')
-rw-r--r-- | net/ipv6/ip6_tunnel.c | 1 |
1 files changed, 1 insertions, 0 deletions
diff --git a/net/ipv6/ip6_tunnel.c b/net/ipv6/ip6_tunnel.c index 9031e521c1d..cd940647bd1 100644 --- a/net/ipv6/ip6_tunnel.c +++ b/net/ipv6/ip6_tunnel.c @@ -550,6 +550,7 @@ ip4ip6_err(struct sk_buff *skb, struct inet6_skb_parm *opt, ip_rt_put(rt); goto out; } + skb2->dst = (struct dst_entry *)rt; } else { ip_rt_put(rt); if (ip_route_input(skb2, eiph->daddr, eiph->saddr, eiph->tos, |