]> git.hungrycats.org Git - linux/commitdiff
[PKT_SCHED]: Fix slab corruption in cbq_destroy
authorThomas Graf <tgraf@suug.ch>
Thu, 16 Sep 2004 06:13:12 +0000 (23:13 -0700)
committerDavid S. Miller <davem@nuts.davemloft.net>
Thu, 16 Sep 2004 06:13:12 +0000 (23:13 -0700)
Fixes slab corruption in cbq_destroy. cbq_destroy_filters and
qdisc_put_rtab(q->link.R_tab) are already called in cbq_destroy_class.
The latter lead to a slab corruption due to repeated freeing of
q->link.R_tab because q->link is part of q->classes. Problem introduced
in 1.21.

Signed-off-by: Thomas Graf <tgraf@suug.ch>
Signed-off-by: Patrick McHardy <kaber@trash.net>
Signed-off-by: David S. Miller <davem@davemloft.net>
net/sched/sch_cbq.c

index 192ad0a9b904f2ce990c75423cae11ad8836eb13..bf59fe31059aa69fb249e08ed9b35772af3b358d 100644 (file)
@@ -1770,10 +1770,6 @@ cbq_destroy(struct Qdisc* sch)
 #ifdef CONFIG_NET_CLS_POLICE
        q->rx_class = NULL;
 #endif
-       for (h = 0; h < 16; h++) {
-               for (cl = q->classes[h]; cl; cl = cl->next)
-                       cbq_destroy_filters(cl);
-       }
 
        for (h = 0; h < 16; h++) {
                struct cbq_class *next;
@@ -1783,8 +1779,6 @@ cbq_destroy(struct Qdisc* sch)
                        cbq_destroy_class(sch, cl);
                }
        }
-
-       qdisc_put_rtab(q->link.R_tab);
 }
 
 static void cbq_put(struct Qdisc *sch, unsigned long arg)