Skip to content

Commit

Permalink
netfilter: ipvs: fix dst leak in __ip_vs_addr_is_local_v6
Browse files Browse the repository at this point in the history
After call to ip6_route_output() we must release dst or we leak it.

Also should test dst->error, as ip6_route_output() never returns NULL.

Use boolean while we are at it.

Signed-off-by: Eric Dumazet <edumazet@google.com>
Signed-off-by: Pablo Neira Ayuso <pablo@netfilter.org>
  • Loading branch information
Eric Dumazet authored and Pablo Neira Ayuso committed Jun 25, 2012
1 parent ef5b6e1 commit c24584c
Showing 1 changed file with 7 additions and 7 deletions.
14 changes: 7 additions & 7 deletions net/netfilter/ipvs/ip_vs_ctl.c
Original file line number Diff line number Diff line change
Expand Up @@ -76,19 +76,19 @@ static void __ip_vs_del_service(struct ip_vs_service *svc);

#ifdef CONFIG_IP_VS_IPV6
/* Taken from rt6_fill_node() in net/ipv6/route.c, is there a better way? */
static int __ip_vs_addr_is_local_v6(struct net *net,
const struct in6_addr *addr)
static bool __ip_vs_addr_is_local_v6(struct net *net,
const struct in6_addr *addr)
{
struct rt6_info *rt;
struct flowi6 fl6 = {
.daddr = *addr,
};
struct dst_entry *dst = ip6_route_output(net, NULL, &fl6);
bool is_local;

rt = (struct rt6_info *)ip6_route_output(net, NULL, &fl6);
if (rt && rt->dst.dev && (rt->dst.dev->flags & IFF_LOOPBACK))
return 1;
is_local = !dst->error && dst->dev && (dst->dev->flags & IFF_LOOPBACK);

return 0;
dst_release(dst);
return is_local;
}
#endif

Expand Down

0 comments on commit c24584c

Please sign in to comment.