Skip to content

Commit ecddc52

Browse files
q2venkuba-moo
authored andcommitted
tcp: Fix dst leak in tcp_v6_connect().
If a socket is bound to a wildcard address, tcp_v[46]_connect() updates it with a non-wildcard address based on the route lookup. After bhash2 was introduced in the cited commit, we must call inet_bhash2_update_saddr() to update the bhash2 entry as well. If inet_bhash2_update_saddr() fails, we must release the refcount for dst by ip_route_connect() or ip6_dst_lookup_flow(). While tcp_v4_connect() calls ip_rt_put() in the error path, tcp_v6_connect() does not call dst_release(). Let's call dst_release() when inet_bhash2_update_saddr() fails in tcp_v6_connect(). Fixes: 28044fc ("net: Add a bhash2 table hashed by port and address") Reported-by: Damiano Melotti <melotti@google.com> Signed-off-by: Kuniyuki Iwashima <kuniyu@google.com> Reviewed-by: Eric Dumazet <edumazet@google.com> Link: https://patch.msgid.link/20260506070443.1699879-1-kuniyu@google.com Signed-off-by: Jakub Kicinski <kuba@kernel.org>
1 parent 019c892 commit ecddc52

1 file changed

Lines changed: 3 additions & 1 deletion

File tree

net/ipv6/tcp_ipv6.c

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -288,8 +288,10 @@ static int tcp_v6_connect(struct sock *sk, struct sockaddr_unsized *uaddr,
288288
saddr = &fl6->saddr;
289289

290290
err = inet_bhash2_update_saddr(sk, saddr, AF_INET6);
291-
if (err)
291+
if (err) {
292+
dst_release(dst);
292293
goto failure;
294+
}
293295
}
294296

295297
/* set the source address */

0 commit comments

Comments
 (0)