Re: [PATCH net] ppp: fix memory leak in pad_compress_skb
Eric Dumazet <[email protected]> Wed, 3 Sep 2025 04:18:38 -0700
| Newsgroups | org.kernel.vger.linux-ppp,org.kernel.vger.linux-kernel,org.kernel.vger.netdev |
|---|---|
| Message-ID | <CANn89iLKpJaF0VcWxqCUuouJw8mZ4Fjk_cc89yMmuZWCLx70-w@mail.gmail.com> |
On Wed, Sep 3, 2025 at 3:07 AM Qingfang Deng <[email protected]> wrote: > > If alloc_skb() fails in pad_compress_skb(), it returns NULL without > releasing the old skb. The caller does: > > skb = pad_compress_skb(ppp, skb); > if (!skb) > goto drop; > > drop: > kfree_skb(skb); > > When pad_compress_skb() returns NULL, the reference to the old skb is > lost and kfree_skb(skb) ends up doing nothing, leading to a memory leak. > > Align pad_compress_skb() semantics with realloc(): only free the old > skb if allocation and compression succeed. At the call site, use the > new_skb variable so the original skb is not lost when pad_compress_skb() > fails. > > Fixes: b3f9b92a6ec1 ("[PPP]: add PPP MPPE encryption module") > Signed-off-by: Qingfang Deng <[email protected]> > --- Reviewed-by: Eric Dumazet <[email protected]>