summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorSanghyun Park <sanghyun.park.cnu@gmail.com>2026-07-22 16:28:38 +0900
committerSteffen Klassert <steffen.klassert@secunet.com>2026-07-23 10:07:21 +0200
commit2aed51fc58d9ce450e2c116efb956160fd06fa02 (patch)
tree206bc78a832dbd4f9dcc4530770712a816c04b54
parent763fe700b7c58ad64fe5202c5638848244dd4127 (diff)
downloadlinux-next-2aed51fc58d9ce450e2c116efb956160fd06fa02.tar.gz
linux-next-2aed51fc58d9ce450e2c116efb956160fd06fa02.zip
xfrm: Fix skb double-free in xfrm_dev_direct_output()
A return value other than 1 from local_out() means that the skb has been consumed or its ownership was transferred. xfrm_dev_direct_output() nevertheless frees the skb on this path, causing a double-free when netfilter drops the packet and invalidating any other owner. Return the local_out() result directly, matching the ownership handling in xfrm_output_resume(). Fixes: 5eddd76ec2fd ("xfrm: fix tunnel mode TX datapath in packet offload mode") Signed-off-by: Sanghyun Park <sanghyun.park.cnu@gmail.com> Signed-off-by: Steffen Klassert <steffen.klassert@secunet.com>
-rw-r--r--net/xfrm/xfrm_output.c4
1 files changed, 1 insertions, 3 deletions
diff --git a/net/xfrm/xfrm_output.c b/net/xfrm/xfrm_output.c
index cc35c2fcbbe0..e305ba32e356 100644
--- a/net/xfrm/xfrm_output.c
+++ b/net/xfrm/xfrm_output.c
@@ -636,10 +636,8 @@ static int xfrm_dev_direct_output(struct sock *sk, struct xfrm_state *x,
nf_reset_ct(skb);
err = skb_dst(skb)->ops->local_out(net, sk, skb);
- if (unlikely(err != 1)) {
- kfree_skb(skb);
+ if (unlikely(err != 1))
return err;
- }
/* In transport mode, network destination is
* directly reachable, while in tunnel mode,