NetBSD-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: kern/60487: netinet6: fragment accounting leak



Another report forwarded to us describes a similar accounting leak for
frag6_nfragpackets:

    267 	if (q6 == &ip6q) {
    268 		/*
    269 		 * the first fragment to arrive, create a reassembly queue.
    270 		 */
    271 		first_frag = 1;
...
    284 		frag6_nfragpackets++;
    285 
    286 		q6 = kmem_intr_zalloc(sizeof(struct ip6q), KM_NOSLEEP);
    287 		if (q6 == NULL) {
    288 			goto dropfrag;
    289 		}
...
    301 	}
...
    313 	/*
    314 	 * Check that the reassembled packet would not exceed 65535 bytes
    315 	 * in size. If it would exceed, discard the fragment and return an
    316 	 * ICMP error.
    317 	 */
    318 	if (q6->ip6q_unfrglen >= 0) {
    319 		/* The 1st fragment has already arrived. */
    320 		if (q6->ip6q_unfrglen + fragoff + frgpartlen > IPV6_MAXPACKET) {
    321 			mutex_exit(&frag6_lock);
    322 			icmp6_error(m, ICMP6_PARAM_PROB, ICMP6_PARAMPROB_HEADER,
    323 			    offset - sizeof(struct ip6_frag) +
    324 			    offsetof(struct ip6_frag, ip6f_offlg));
    325 			goto done;
    326 		}
    327 	} else if (fragoff + frgpartlen > IPV6_MAXPACKET) {
    328 		mutex_exit(&frag6_lock);
    329 		icmp6_error(m, ICMP6_PARAM_PROB, ICMP6_PARAMPROB_HEADER,
    330 		    offset - sizeof(struct ip6_frag) +
    331 		    offsetof(struct ip6_frag, ip6f_offlg));
    332 		goto done;
    333 	}

https://nxr.netbsd.org/xref/src/sys/netinet6/frag6.c?r=1.79#267

In these error branches, the claim is that frag6_nfragpackets leaks.
So perhaps we should have

+	if (first_frag)
+		frag6_dropfrag(q6);
 	goto done;

in these branches.



Home | Main Index | Thread Index | Old Index