[IPV6]: dst_entry leak in ip4ip6_err. (resend)
authorDenis V. Lunev <den@openvz.org>
Tue, 19 Feb 2008 04:49:36 +0000 (20:49 -0800)
committerDavid S. Miller <davem@davemloft.net>
Tue, 19 Feb 2008 04:49:36 +0000 (20:49 -0800)
The result of the ip_route_output is not assigned to skb. This means that
- it is leaked
- possible OOPS below dereferrencing skb->dst
- no ICMP message for this case

Signed-off-by: Denis V. Lunev <den@openvz.org>
Signed-off-by: David S. Miller <davem@davemloft.net>
net/ipv6/ip6_tunnel.c

index 9031e52..cd94064 100644 (file)
@@ -550,6 +550,7 @@ ip4ip6_err(struct sk_buff *skb, struct inet6_skb_parm *opt,
                        ip_rt_put(rt);
                        goto out;
                }
+               skb2->dst = (struct dst_entry *)rt;
        } else {
                ip_rt_put(rt);
                if (ip_route_input(skb2, eiph->daddr, eiph->saddr, eiph->tos,