Revision e7820e39b7d19b9fe1928fc19de9361b44150ca6 authored by Eric Dumazet on 21 November 2014, 19:47:16 UTC, committed by David S. Miller on 21 November 2014, 20:26:32 UTC
Not sure what I was thinking, but doing anything after
releasing a refcount is suicidal or/and embarrassing.

By the time we set skb->fclone to SKB_FCLONE_FREE, another cpu
could have released last reference and freed whole skb.

We potentially corrupt memory or trap if CONFIG_DEBUG_PAGEALLOC is set.

Reported-by: Chris Mason <clm@fb.com>
Fixes: ce1a4ea3f1258 ("net: avoid one atomic operation in skb_clone()")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Cc: Sabrina Dubroca <sd@queasysnail.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
1 parent 892d6eb
History
File Mode Size
configs
dig
hp
include
kernel
kvm
lib
mm
oprofile
pci
scripts
sn
uv
Kconfig -rw-r--r-- 16.1 KB
Kconfig.debug -rw-r--r-- 1.9 KB
Makefile -rw-r--r-- 3.2 KB
install.sh -rw-r--r-- 958 bytes
module.lds -rw-r--r-- 355 bytes

back to top