Page MenuHomeFreeBSD

udp: Fix a use-after-free in udp_multi_input()
ClosedPublic

Authored by markj on Dec 15 2021, 5:19 PM.
Tags
None
Referenced Files
Unknown Object (File)
Thu, Dec 11, 11:09 PM
Unknown Object (File)
Thu, Dec 11, 11:09 PM
Unknown Object (File)
Thu, Dec 11, 11:08 PM
Unknown Object (File)
Thu, Dec 11, 2:17 PM
Unknown Object (File)
Thu, Dec 11, 3:44 AM
Unknown Object (File)
Wed, Dec 10, 9:47 AM
Unknown Object (File)
Tue, Dec 9, 5:05 PM
Unknown Object (File)
Sun, Nov 23, 2:57 AM

Details

Summary

"ip" is a pointer into the mbuf chain, so we shouldn't access it after
the chain is freed.

Fix style at the call site.

Reported by: syzbot+7c8258509722af1b6145@syzkaller.appspotmail.com
Fixes: de2d47842e88 ("SMR protection for inpcbs")

Diff Detail

Repository
rS FreeBSD src repository - subversion
Lint
Lint Passed
Unit
No Test Coverage
Build Status
Buildable 43380
Build 40268: arc lint + arc unit