diff options
| -rw-r--r-- | meta/recipes-support/libnl/libnl/0001-fix-double-free-caused-by-freeing-link-af_data-in-rt.patch | 41 | ||||
| -rw-r--r-- | meta/recipes-support/libnl/libnl_3.2.22.bb | 4 |
2 files changed, 44 insertions, 1 deletions
diff --git a/meta/recipes-support/libnl/libnl/0001-fix-double-free-caused-by-freeing-link-af_data-in-rt.patch b/meta/recipes-support/libnl/libnl/0001-fix-double-free-caused-by-freeing-link-af_data-in-rt.patch new file mode 100644 index 0000000000..6d2c8ff72d --- /dev/null +++ b/meta/recipes-support/libnl/libnl/0001-fix-double-free-caused-by-freeing-link-af_data-in-rt.patch | |||
| @@ -0,0 +1,41 @@ | |||
| 1 | From 6f37b439af7e96104aadd8ec3ae8d3882df8d102 Mon Sep 17 00:00:00 2001 | ||
| 2 | From: Jiri Pirko <jiri@resnulli.us> | ||
| 3 | Date: Wed, 21 Aug 2013 14:40:34 +0200 | ||
| 4 | Subject: [PATCH] fix double free caused by freeing link af_data in | ||
| 5 | rtnl_link_set_family() | ||
| 6 | |||
| 7 | Introduced by commit 8026fe2e3a9089eff3f5a06ee6e3cc78d96334ed ("link: | ||
| 8 | Free and realloc af specific data upon rtnl_link_set_family()") | ||
| 9 | |||
| 10 | link->l_af_data[link->l_af_ops->ao_family] is freed here but not set to | ||
| 11 | zero. That leads to double free made by link_free_data->do_foreach_af. | ||
| 12 | |||
| 13 | Fix this by setting link->l_af_data[link->l_af_ops->ao_family] to zero | ||
| 14 | rigth after free. | ||
| 15 | |||
| 16 | Signed-off-by: Jiri Pirko <jiri@resnulli.us> | ||
| 17 | Signed-off-by: Thomas Graf <tgraf@suug.ch> | ||
| 18 | --- | ||
| 19 | lib/route/link.c | 4 +++- | ||
| 20 | 1 file changed, 3 insertions(+), 1 deletion(-) | ||
| 21 | |||
| 22 | diff --git a/lib/route/link.c b/lib/route/link.c | ||
| 23 | index a73e1db..0bb90a0 100644 | ||
| 24 | --- a/lib/route/link.c | ||
| 25 | +++ b/lib/route/link.c | ||
| 26 | @@ -1762,9 +1762,11 @@ void rtnl_link_set_family(struct rtnl_link *link, int family) | ||
| 27 | link->l_family = family; | ||
| 28 | link->ce_mask |= LINK_ATTR_FAMILY; | ||
| 29 | |||
| 30 | - if (link->l_af_ops) | ||
| 31 | + if (link->l_af_ops) { | ||
| 32 | af_free(link, link->l_af_ops, | ||
| 33 | link->l_af_data[link->l_af_ops->ao_family], NULL); | ||
| 34 | + link->l_af_data[link->l_af_ops->ao_family] = NULL; | ||
| 35 | + } | ||
| 36 | |||
| 37 | link->l_af_ops = af_lookup_and_alloc(link, family); | ||
| 38 | } | ||
| 39 | -- | ||
| 40 | 1.8.4 | ||
| 41 | |||
diff --git a/meta/recipes-support/libnl/libnl_3.2.22.bb b/meta/recipes-support/libnl/libnl_3.2.22.bb index 30f85b2995..3c31b1ac86 100644 --- a/meta/recipes-support/libnl/libnl_3.2.22.bb +++ b/meta/recipes-support/libnl/libnl_3.2.22.bb | |||
| @@ -12,7 +12,9 @@ DEPENDS = "flex-native bison-native" | |||
| 12 | SRC_URI = "http://www.infradead.org/~tgr/${BPN}/files/${BP}.tar.gz \ | 12 | SRC_URI = "http://www.infradead.org/~tgr/${BPN}/files/${BP}.tar.gz \ |
| 13 | file://fix-pktloc_syntax_h-race.patch \ | 13 | file://fix-pktloc_syntax_h-race.patch \ |
| 14 | file://fix-pc-file.patch \ | 14 | file://fix-pc-file.patch \ |
| 15 | file://fix-lib-cache_mngr.c-two-parentheses-bugs.patch" | 15 | file://fix-lib-cache_mngr.c-two-parentheses-bugs.patch \ |
| 16 | file://0001-fix-double-free-caused-by-freeing-link-af_data-in-rt.patch \ | ||
| 17 | " | ||
| 16 | 18 | ||
| 17 | SRC_URI[md5sum] = "2e1c889494d274aca24ce5f6a748e66e" | 19 | SRC_URI[md5sum] = "2e1c889494d274aca24ce5f6a748e66e" |
| 18 | SRC_URI[sha256sum] = "c7c5f267dfeae0c1a530bf96b71fb7c8dbbb07d54beef49b6712d8d6166f629b" | 20 | SRC_URI[sha256sum] = "c7c5f267dfeae0c1a530bf96b71fb7c8dbbb07d54beef49b6712d8d6166f629b" |
