1
0
Fork 0

net, lapb: convert lapb_cb.refcnt from atomic_t to refcount_t

refcount_t type and corresponding API should be
used instead of atomic_t when the variable is used as
a reference counter. This allows to avoid accidental
refcounter overflows that might lead to use-after-free
situations.

Signed-off-by: Elena Reshetova <elena.reshetova@intel.com>
Signed-off-by: Hans Liljestrand <ishkamiel@gmail.com>
Signed-off-by: Kees Cook <keescook@chromium.org>
Signed-off-by: David Windsor <dwindsor@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
zero-colors
Reshetova, Elena 2017-07-04 15:53:08 +03:00 committed by David S. Miller
parent 7b93640502
commit 0408c58be5
2 changed files with 5 additions and 4 deletions

View File

@ -1,6 +1,7 @@
#ifndef _LAPB_H #ifndef _LAPB_H
#define _LAPB_H #define _LAPB_H
#include <linux/lapb.h> #include <linux/lapb.h>
#include <linux/refcount.h>
#define LAPB_HEADER_LEN 20 /* LAPB over Ethernet + a bit more */ #define LAPB_HEADER_LEN 20 /* LAPB over Ethernet + a bit more */
@ -101,7 +102,7 @@ struct lapb_cb {
struct lapb_frame frmr_data; struct lapb_frame frmr_data;
unsigned char frmr_type; unsigned char frmr_type;
atomic_t refcnt; refcount_t refcnt;
}; };
/* lapb_iface.c */ /* lapb_iface.c */

View File

@ -54,12 +54,12 @@ static void lapb_free_cb(struct lapb_cb *lapb)
static __inline__ void lapb_hold(struct lapb_cb *lapb) static __inline__ void lapb_hold(struct lapb_cb *lapb)
{ {
atomic_inc(&lapb->refcnt); refcount_inc(&lapb->refcnt);
} }
static __inline__ void lapb_put(struct lapb_cb *lapb) static __inline__ void lapb_put(struct lapb_cb *lapb)
{ {
if (atomic_dec_and_test(&lapb->refcnt)) if (refcount_dec_and_test(&lapb->refcnt))
lapb_free_cb(lapb); lapb_free_cb(lapb);
} }
@ -136,7 +136,7 @@ static struct lapb_cb *lapb_create_cb(void)
lapb->mode = LAPB_DEFAULT_MODE; lapb->mode = LAPB_DEFAULT_MODE;
lapb->window = LAPB_DEFAULT_WINDOW; lapb->window = LAPB_DEFAULT_WINDOW;
lapb->state = LAPB_STATE_0; lapb->state = LAPB_STATE_0;
atomic_set(&lapb->refcnt, 1); refcount_set(&lapb->refcnt, 1);
out: out:
return lapb; return lapb;
} }