OSDN Git Service

sfc: fix use-after-free in efx_tc_flower_record_encap_match()
authorEdward Cree <ecree.xilinx@gmail.com>
Fri, 12 May 2023 15:35:58 +0000 (16:35 +0100)
committerDavid S. Miller <davem@davemloft.net>
Sat, 13 May 2023 19:58:17 +0000 (20:58 +0100)
When writing error messages to extack for pseudo collisions, we can't
 use encap->type as encap has already been freed.  Fortunately the
 same value is stored in local variable em_type, so use that instead.

Fixes: 3c9561c0a5b9 ("sfc: support TC decap rules matching on enc_ip_tos")
Reported-by: Simon Horman <simon.horman@corigine.com>
Signed-off-by: Edward Cree <ecree.xilinx@gmail.com>
Reviewed-by: Simon Horman <simon.horman@corigine.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
drivers/net/ethernet/sfc/tc.c

index da684b4..6dfbdb3 100644 (file)
@@ -504,7 +504,7 @@ static int efx_tc_flower_record_encap_match(struct efx_nic *efx,
                        if (em_type != EFX_TC_EM_PSEUDO_MASK) {
                                NL_SET_ERR_MSG_FMT_MOD(extack,
                                                       "%s encap match conflicts with existing pseudo(MASK) entry",
-                                                      encap->type ? "Pseudo" : "Direct");
+                                                      em_type ? "Pseudo" : "Direct");
                                return -EEXIST;
                        }
                        if (child_ip_tos_mask != old->child_ip_tos_mask) {
@@ -525,7 +525,7 @@ static int efx_tc_flower_record_encap_match(struct efx_nic *efx,
                default: /* Unrecognised pseudo-type.  Just say no */
                        NL_SET_ERR_MSG_FMT_MOD(extack,
                                               "%s encap match conflicts with existing pseudo(%d) entry",
-                                              encap->type ? "Pseudo" : "Direct",
+                                              em_type ? "Pseudo" : "Direct",
                                               old->type);
                        return -EEXIST;
                }