From 362cf792a093d4bef82e06e0fbd0823f0f356af4 Mon Sep 17 00:00:00 2001 From: Eric Dumazet Date: Wed, 20 Feb 2019 15:44:38 +0000 Subject: [PATCH] net: fix possible overflow in __sk_mem_raise_allocated() mainline inclusion from mainline-v5.0 commit 5bf325a53202 category: bugfix bugzilla: 9551 CVE: NA ------------------------------------------------- With many active TCP sockets, fat TCP sockets could fool __sk_mem_raise_allocated() thanks to an overflow. They would increase their share of the memory, instead of decreasing it. Signed-off-by: Eric Dumazet Signed-off-by: David S. Miller Signed-off-by: Shangli Reviewed-by: Mao Wenan Signed-off-by: Yang Yingliang --- include/net/sock.h | 2 +- net/core/sock.c | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/include/net/sock.h b/include/net/sock.h index 6a0ecdea5e8e..a6f19c40459f 100644 --- a/include/net/sock.h +++ b/include/net/sock.h @@ -1266,7 +1266,7 @@ static inline void sk_sockets_allocated_inc(struct sock *sk) percpu_counter_inc(sk->sk_prot->sockets_allocated); } -static inline int +static inline u64 sk_sockets_allocated_read_positive(struct sock *sk) { return percpu_counter_read_positive(sk->sk_prot->sockets_allocated); diff --git a/net/core/sock.c b/net/core/sock.c index 79306a9094a6..b03649737ea8 100644 --- a/net/core/sock.c +++ b/net/core/sock.c @@ -2433,7 +2433,7 @@ int __sk_mem_raise_allocated(struct sock *sk, int size, int amt, int kind) } if (sk_has_memory_pressure(sk)) { - int alloc; + u64 alloc; if (!sk_under_memory_pressure(sk)) return 1; -- GitLab