]> git.proxmox.com Git - mirror_ubuntu-kernels.git/commit
ptr_ring: use kmalloc_array()
authorEric Dumazet <edumazet@google.com>
Wed, 16 Aug 2017 17:36:47 +0000 (10:36 -0700)
committerDavid S. Miller <davem@davemloft.net>
Wed, 16 Aug 2017 23:28:47 +0000 (16:28 -0700)
commit81fbfe8adaf38d4f5a98c19bebfd41c5d6acaee8
treed6b6fc17c19f0df3e916e55726dee279c055deb6
parent120e9dabaf551c6dc03d3a10a1f026376cb1811c
ptr_ring: use kmalloc_array()

As found by syzkaller, malicious users can set whatever tx_queue_len
on a tun device and eventually crash the kernel.

Lets remove the ALIGN(XXX, SMP_CACHE_BYTES) thing since a small
ring buffer is not fast anyway.

Fixes: 2e0ab8ca83c1 ("ptr_ring: array based FIFO for pointers")
Signed-off-by: Eric Dumazet <edumazet@google.com>
Reported-by: Dmitry Vyukov <dvyukov@google.com>
Cc: Michael S. Tsirkin <mst@redhat.com>
Cc: Jason Wang <jasowang@redhat.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
include/linux/ptr_ring.h
include/linux/skb_array.h