mirror of
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git
synced 2026-08-30 12:13:51 -04:00
hinic3: fix use-after-free on DMA mapping failure
If hinic3_tx_map_skb() fails in hinic3_send_one_skb(), the skb is freed, but tx_info->skb was set before the mapping attempt and is not cleared. The SQ producer index is rolled back, so later transmissions normally overwrite the entry. If the interface is brought down first, hinic3_free_txqs_res() calls free_all_tx_skbs(). It scans the entire tx_info array and finds the stale pointer. hinic3_tx_unmap_skb() then dereferences the freed skb in skb_shinfo(), before it is freed again. Set tx_info->skb and its WQEBB count only after DMA mapping succeeds, preventing the stale pointer from reaching free_all_tx_skbs(). Cc: stable+noautosel@kernel.org # untested fix to unlikely driver error path Signed-off-by: Xuanqiang Luo <luoxuanqiang@kylinos.cn> Reviewed-by: Fan Gong <gongfan1@huawei.com> Reviewed-by: Simon Horman <horms@kernel.org> Link: https://patch.msgid.link/20260710090527.58354-3-xuanqiang.luo@linux.dev Signed-off-by: Jakub Kicinski <kuba@kernel.org>
This commit is contained in:
committed by
Jakub Kicinski
parent
be9381d577
commit
dd5de39af5
@@ -578,8 +578,6 @@ static netdev_tx_t hinic3_send_one_skb(struct sk_buff *skb,
|
||||
*wqe_combo.task = task;
|
||||
|
||||
tx_info = &txq->tx_info[pi];
|
||||
tx_info->skb = skb;
|
||||
tx_info->wqebb_cnt = wqebb_cnt;
|
||||
|
||||
err = hinic3_tx_map_skb(netdev, skb, txq, tx_info, &wqe_combo);
|
||||
if (err) {
|
||||
@@ -589,6 +587,9 @@ static netdev_tx_t hinic3_send_one_skb(struct sk_buff *skb,
|
||||
goto err_drop_pkt;
|
||||
}
|
||||
|
||||
tx_info->skb = skb;
|
||||
tx_info->wqebb_cnt = wqebb_cnt;
|
||||
|
||||
netif_subqueue_sent(netdev, txq->sq->q_id, skb->len);
|
||||
netif_subqueue_maybe_stop(netdev, txq->sq->q_id,
|
||||
hinic3_wq_free_wqebbs(&txq->sq->wq),
|
||||
|
||||
Reference in New Issue
Block a user