Skip to content

Commit b7f47c7

Browse files
edumazetgregkh
authored andcommitted
ping: implement proper locking
commit 43a6684519ab0a6c52024b5e25322476cabad893 upstream. We got a report of yet another bug in ping http://www.openwall.com/lists/oss-security/2017/03/24/6 ->disconnect() is not called with socket lock held. Fix this by acquiring ping rwlock earlier. Thanks to Daniel, Alexander and Andrey for letting us know this problem. Fixes: c319b4d ("net: ipv4: add IPPROTO_ICMP socket kind") Signed-off-by: Eric Dumazet <edumazet@google.com> Reported-by: Daniel Jiang <danieljiang0415@gmail.com> Reported-by: Solar Designer <solar@openwall.com> Reported-by: Andrey Konovalov <andreyknvl@google.com> Signed-off-by: David S. Miller <davem@davemloft.net> Cc: Ben Hutchings <ben.hutchings@codethink.co.uk> Signed-off-by: Greg Kroah-Hartman <gregkh@linuxfoundation.org>
1 parent a7544fd commit b7f47c7

1 file changed

Lines changed: 3 additions & 2 deletions

File tree

net/ipv4/ping.c

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -154,17 +154,18 @@ void ping_hash(struct sock *sk)
154154
void ping_unhash(struct sock *sk)
155155
{
156156
struct inet_sock *isk = inet_sk(sk);
157+
157158
pr_debug("ping_unhash(isk=%p,isk->num=%u)\n", isk, isk->inet_num);
159+
write_lock_bh(&ping_table.lock);
158160
if (sk_hashed(sk)) {
159-
write_lock_bh(&ping_table.lock);
160161
hlist_nulls_del(&sk->sk_nulls_node);
161162
sk_nulls_node_init(&sk->sk_nulls_node);
162163
sock_put(sk);
163164
isk->inet_num = 0;
164165
isk->inet_sport = 0;
165166
sock_prot_inuse_add(sock_net(sk), sk->sk_prot, -1);
166-
write_unlock_bh(&ping_table.lock);
167167
}
168+
write_unlock_bh(&ping_table.lock);
168169
}
169170
EXPORT_SYMBOL_GPL(ping_unhash);
170171

0 commit comments

Comments
 (0)