Re: [PATCH net] ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
| Newsgroups | org.kernel.vger.netdev,org.kernel.vger.linux-kernel,org.kernel.vger.stable |
|---|---|
| Message-ID | <178742940838.1814690.12298036275271719275.git-patchwork-notify@kernel.org> |
Hello: This patch was applied to netdev/net.git (main) by Jakub Kicinski <[email protected]>: On Wed, 19 Aug 2026 13:43:39 +0300 you wrote: > In collect_md mode ipip_tunnel_rcv() returns 0 without freeing the skb > when ip_tun_rx_dst() fails to allocate the metadata_dst. ipip_rcv() and > mplsip_rcv() are registered as xfrm_tunnel handlers, so tunnel4_rcv() > and tunnelmpls4_rcv() read the zero return as "the packet has been > consumed" and do not free it either. The skb is leaked. > > The other tunnel drivers all dispose of the packet at this point: > ip6_tunnel.c jumps to its drop label, ip_gre.c and ip6_gre.c return > PACKET_REJECT, which makes gre_rcv() free the skb. Only ipip returns 0. > > [...] Here is the summary with links: - [net] ipip: fix skb leak in collect_md mode when metadata_dst allocation fails https://git.kernel.org/netdev/net/c/6776efe4a52f You are awesome, thank you! -- Deet-doot-dot, I am a bot. https://korg.docs.kernel.org/patchwork/pwbot.html