Commit 4e3ae00100945d39e1f83b7c0179a114ccf55759

Authored by Erik Hugne
Committed by David S. Miller
1 parent aab0c0e62e

tipc: reinitialize pointer after skb linearize

The msg pointer into header may change after skb linearization.
We must reinitialize it after calling skb_linearize to prevent
operating on a freed or invalid pointer.

Signed-off-by: Erik Hugne <erik.hugne@ericsson.com>
Reported-by: Tamás Végh <tamas.vegh@ericsson.com>
Acked-by: Ying Xue <ying.xue@windriver.com>
Signed-off-by: David S. Miller <davem@davemloft.net>

Showing 1 changed file with 1 additions and 0 deletions Side-by-side Diff

... ... @@ -539,6 +539,7 @@
539 539 *err = -TIPC_ERR_NO_NAME;
540 540 if (skb_linearize(skb))
541 541 return false;
  542 + msg = buf_msg(skb);
542 543 if (msg_reroute_cnt(msg))
543 544 return false;
544 545 dnode = addr_domain(net, msg_lookup_scope(msg));