Re: [PATCH net] ipip: fix skb leak in collect_md mode when metadata_dst allocation fails

[email protected]
Newsgroups org.kernel.vger.netdev,org.kernel.vger.linux-kernel,org.kernel.vger.stable
Message-ID <178742940838.1814690.12298036275271719275.git-patchwork-notify@kernel.org>
Hello:

This patch was applied to netdev/net.git (main)
by Jakub Kicinski <[email protected]>:

On Wed, 19 Aug 2026 13:43:39 +0300 you wrote:
> In collect_md mode ipip_tunnel_rcv() returns 0 without freeing the skb
> when ip_tun_rx_dst() fails to allocate the metadata_dst. ipip_rcv() and
> mplsip_rcv() are registered as xfrm_tunnel handlers, so tunnel4_rcv()
> and tunnelmpls4_rcv() read the zero return as "the packet has been
> consumed" and do not free it either. The skb is leaked.
> 
> The other tunnel drivers all dispose of the packet at this point:
> ip6_tunnel.c jumps to its drop label, ip_gre.c and ip6_gre.c return
> PACKET_REJECT, which makes gre_rcv() free the skb. Only ipip returns 0.
> 
> [...]

Here is the summary with links:
  - [net] ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
    https://git.kernel.org/netdev/net/c/6776efe4a52f

You are awesome, thank you!
-- 
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.