Skip to content

Commit 43a6684

Browse files
edumazetdavem330
authored andcommitted
ping: implement proper locking
We got a report of yet another bug in ping http://www.openwall.com/lists/oss-security/2017/03/24/6 ->disconnect() is not called with socket lock held. Fix this by acquiring ping rwlock earlier. Thanks to Daniel, Alexander and Andrey for letting us know this problem. Fixes: c319b4d ("net: ipv4: add IPPROTO_ICMP socket kind") Signed-off-by: Eric Dumazet <edumazet@google.com> Reported-by: Daniel Jiang <danieljiang0415@gmail.com> Reported-by: Solar Designer <solar@openwall.com> Reported-by: Andrey Konovalov <andreyknvl@google.com> Signed-off-by: David S. Miller <davem@davemloft.net>
1 parent 13a8cd1 commit 43a6684

1 file changed

Lines changed: 3 additions & 2 deletions

File tree

net/ipv4/ping.c

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -156,17 +156,18 @@ int ping_hash(struct sock *sk)
156156
void ping_unhash(struct sock *sk)
157157
{
158158
struct inet_sock *isk = inet_sk(sk);
159+
159160
pr_debug("ping_unhash(isk=%p,isk->num=%u)\n", isk, isk->inet_num);
161+
write_lock_bh(&ping_table.lock);
160162
if (sk_hashed(sk)) {
161-
write_lock_bh(&ping_table.lock);
162163
hlist_nulls_del(&sk->sk_nulls_node);
163164
sk_nulls_node_init(&sk->sk_nulls_node);
164165
sock_put(sk);
165166
isk->inet_num = 0;
166167
isk->inet_sport = 0;
167168
sock_prot_inuse_add(sock_net(sk), sk->sk_prot, -1);
168-
write_unlock_bh(&ping_table.lock);
169169
}
170+
write_unlock_bh(&ping_table.lock);
170171
}
171172
EXPORT_SYMBOL_GPL(ping_unhash);
172173

0 commit comments

Comments
 (0)