macsec: fix use-after-free of skb during RX
authorAndreas Steinmetz <ast@domdv.de>
Sun, 30 Jun 2019 20:46:42 +0000 (22:46 +0200)
committerDavid S. Miller <davem@davemloft.net>
Tue, 2 Jul 2019 21:12:29 +0000 (14:12 -0700)
Fix use-after-free of skb when rx_handler returns RX_HANDLER_PASS.

Signed-off-by: Andreas Steinmetz <ast@domdv.de>
Acked-by: Willem de Bruijn <willemb@google.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
drivers/net/macsec.c

index 75aebf65cd09941f462b9f5774d952600358f3ae..8ec73d67712386e1493f8d6a860a96c585708c41 100644 (file)
@@ -1099,10 +1099,9 @@ static rx_handler_result_t macsec_handle_frame(struct sk_buff **pskb)
        }
 
        skb = skb_unshare(skb, GFP_ATOMIC);
-       if (!skb) {
-               *pskb = NULL;
+       *pskb = skb;
+       if (!skb)
                return RX_HANDLER_CONSUMED;
-       }
 
        pulled_sci = pskb_may_pull(skb, macsec_extra_len(true));
        if (!pulled_sci) {