提交 362cf792 编写于 作者: E Eric Dumazet 提交者: Xie XiuQi

net: fix possible overflow in __sk_mem_raise_allocated()

mainline inclusion
from mainline-v5.0
commit 5bf325a53202
category: bugfix
bugzilla: 9551
CVE: NA

-------------------------------------------------

With many active TCP sockets, fat TCP sockets could fool
__sk_mem_raise_allocated() thanks to an overflow.

They would increase their share of the memory, instead
of decreasing it.
Signed-off-by: NEric Dumazet <edumazet@google.com>
Signed-off-by: NDavid S. Miller <davem@davemloft.net>
Signed-off-by: NShangli <shangli1@huawei.com>
Reviewed-by: NMao Wenan <maowenan@huawei.com>
Signed-off-by: NYang Yingliang <yangyingliang@huawei.com>
上级 7c610bb2
......@@ -1266,7 +1266,7 @@ static inline void sk_sockets_allocated_inc(struct sock *sk)
percpu_counter_inc(sk->sk_prot->sockets_allocated);
}
static inline int
static inline u64
sk_sockets_allocated_read_positive(struct sock *sk)
{
return percpu_counter_read_positive(sk->sk_prot->sockets_allocated);
......
......@@ -2433,7 +2433,7 @@ int __sk_mem_raise_allocated(struct sock *sk, int size, int amt, int kind)
}
if (sk_has_memory_pressure(sk)) {
int alloc;
u64 alloc;
if (!sk_under_memory_pressure(sk))
return 1;
......
Markdown is supported
0% .
You are about to add 0 people to the discussion. Proceed with caution.
先完成此消息的编辑!
想要评论请 注册