[3.13.y-ckt stable] Patch "net: graceful exit from netif_alloc_netdev_queues()" has been added to staging queue
Kamal Mostafa
kamal at canonical.com
Thu Aug 6 20:37:11 UTC 2015
This is a note to let you know that I have just added a patch titled
net: graceful exit from netif_alloc_netdev_queues()
to the linux-3.13.y-queue branch of the 3.13.y-ckt extended stable tree
which can be found at:
http://kernel.ubuntu.com/git/ubuntu/linux.git/log/?h=linux-3.13.y-queue
This patch is scheduled to be released in version 3.13.11-ckt25.
If you, or anyone else, feels it should not be added to this tree, please
reply to this email.
For more information about the 3.13.y-ckt tree, see
https://wiki.ubuntu.com/Kernel/Dev/ExtendedStable
Thanks.
-Kamal
------
>From aa24e87d6a4ad7bb90335a32a02dac7c4737310c Mon Sep 17 00:00:00 2001
From: Eric Dumazet <edumazet at google.com>
Date: Mon, 6 Jul 2015 17:13:26 +0200
Subject: net: graceful exit from netif_alloc_netdev_queues()
commit d339727c2b1a10f25e6636670ab6e1841170e328 upstream.
User space can crash kernel with
ip link add ifb10 numtxqueues 100000 type ifb
We must replace a BUG_ON() by proper test and return -EINVAL for
crazy values.
Fixes: 60877a32bce00 ("net: allow large number of tx queues")
Signed-off-by: Eric Dumazet <edumazet at google.com>
Signed-off-by: David S. Miller <davem at davemloft.net>
Signed-off-by: Kamal Mostafa <kamal at canonical.com>
---
net/core/dev.c | 3 ++-
1 file changed, 2 insertions(+), 1 deletion(-)
diff --git a/net/core/dev.c b/net/core/dev.c
index 6c541ec..870b9ec 100644
--- a/net/core/dev.c
+++ b/net/core/dev.c
@@ -5803,7 +5803,8 @@ static int netif_alloc_netdev_queues(struct net_device *dev)
struct netdev_queue *tx;
size_t sz = count * sizeof(*tx);
- BUG_ON(count < 1 || count > 0xffff);
+ if (count < 1 || count > 0xffff)
+ return -EINVAL;
tx = kzalloc(sz, GFP_KERNEL | __GFP_NOWARN | __GFP_REPEAT);
if (!tx) {
--
1.9.1
More information about the kernel-team
mailing list