Return-Path: Received: (majordomo@vger.kernel.org) by vger.kernel.org via listexpand id S1168173AbdDXJnl (ORCPT ); Mon, 24 Apr 2017 05:43:41 -0400 Received: from mail-wm0-f66.google.com ([74.125.82.66]:34934 "EHLO mail-wm0-f66.google.com" rhost-flags-OK-OK-OK-OK) by vger.kernel.org with ESMTP id S1168086AbdDXJnd (ORCPT ); Mon, 24 Apr 2017 05:43:33 -0400 Date: Mon, 24 Apr 2017 11:43:31 +0200 From: Jiri Pirko To: Pan Bian Cc: netdev@vger.kernel.org, linux-kernel@vger.kernel.org Subject: Re: [net 1/1] team: fix memory leaks Message-ID: <20170424094331.GD4126@nanopsycho.orion> References: <1493026612-12383-1-git-send-email-bianpan2016@163.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1493026612-12383-1-git-send-email-bianpan2016@163.com> User-Agent: Mutt/1.7.1 (2016-10-04) Sender: linux-kernel-owner@vger.kernel.org List-ID: X-Mailing-List: linux-kernel@vger.kernel.org Content-Length: 1570 Lines: 49 Plus since you have only one patch, please do not do "1/1" in the email subject. Thanks. Mon, Apr 24, 2017 at 11:36:52AM CEST, bianpan2016@163.com wrote: >In functions team_nl_send_port_list_get() and >team_nl_send_options_get(), pointer skb keeps the return value of >nlmsg_new(). When the call to genlmsg_put() fails, the memory is not >freed(). This will result in memory leak bugs. > >Fixes: 9b00cf2d1024 ("team: implement multipart netlink messages for >options transfers") >Signed-off-by: Pan Bian >--- > drivers/net/team/team.c | 8 ++++++-- > 1 file changed, 6 insertions(+), 2 deletions(-) > >diff --git a/drivers/net/team/team.c b/drivers/net/team/team.c >index f8c81f1..85c0124 100644 >--- a/drivers/net/team/team.c >+++ b/drivers/net/team/team.c >@@ -2361,8 +2361,10 @@ static int team_nl_send_options_get(struct team *team, u32 portid, u32 seq, > > hdr = genlmsg_put(skb, portid, seq, &team_nl_family, flags | NLM_F_MULTI, > TEAM_CMD_OPTIONS_GET); >- if (!hdr) >+ if (!hdr) { >+ nlmsg_free(skb); > return -EMSGSIZE; >+ } > > if (nla_put_u32(skb, TEAM_ATTR_TEAM_IFINDEX, team->dev->ifindex)) > goto nla_put_failure; >@@ -2634,8 +2636,10 @@ static int team_nl_send_port_list_get(struct team *team, u32 portid, u32 seq, > > hdr = genlmsg_put(skb, portid, seq, &team_nl_family, flags | NLM_F_MULTI, > TEAM_CMD_PORT_LIST_GET); >- if (!hdr) >+ if (!hdr) { >+ nlmsg_free(skb); > return -EMSGSIZE; >+ } > > if (nla_put_u32(skb, TEAM_ATTR_TEAM_IFINDEX, team->dev->ifindex)) > goto nla_put_failure; >-- >1.9.1 > >