Commit 8bdc2acd authored by Dan Carpenter's avatar Dan Carpenter Committed by David S. Miller
Browse files

net: sched: Fix use after free in red_enqueue()



We can't use "skb" again after passing it to qdisc_enqueue().  This is
basically identical to commit 2f09707d ("sch_sfb: Also store skb
len before calling child enqueue").

Fixes: d7f4f332 ("sch_red: update backlog as well")
Signed-off-by: default avatarDan Carpenter <dan.carpenter@oracle.com>
Reviewed-by: default avatarEric Dumazet <edumazet@google.com>
Signed-off-by: default avatarDavid S. Miller <davem@davemloft.net>
parent 06a4df58
Loading
Loading
Loading
Loading
+3 −1
Original line number Diff line number Diff line
@@ -72,6 +72,7 @@ static int red_enqueue(struct sk_buff *skb, struct Qdisc *sch,
{
	struct red_sched_data *q = qdisc_priv(sch);
	struct Qdisc *child = q->qdisc;
	unsigned int len;
	int ret;

	q->vars.qavg = red_calc_qavg(&q->parms,
@@ -126,9 +127,10 @@ static int red_enqueue(struct sk_buff *skb, struct Qdisc *sch,
		break;
	}

	len = qdisc_pkt_len(skb);
	ret = qdisc_enqueue(skb, child, to_free);
	if (likely(ret == NET_XMIT_SUCCESS)) {
		qdisc_qstats_backlog_inc(sch, skb);
		sch->qstats.backlog += len;
		sch->q.qlen++;
	} else if (net_xmit_drop_count(ret)) {
		q->stats.pdrop++;