llc: use refcount_inc_not_zero() for llc_sap_find()
authorCong Wang <xiyou.wangcong@gmail.com>
Tue, 7 Aug 2018 19:41:38 +0000 (12:41 -0700)
committerDavid S. Miller <davem@davemloft.net>
Tue, 7 Aug 2018 22:54:00 +0000 (15:54 -0700)
commit0dcb82254d65f72333aa50ad626d1e9665ad093b
tree0624bb5c365884b956d4abaf79d50e87a1406762
parent61ef4b07fcdc30535889990cf4229766502561cf
llc: use refcount_inc_not_zero() for llc_sap_find()

llc_sap_put() decreases the refcnt before deleting sap
from the global list. Therefore, there is a chance
llc_sap_find() could find a sap with zero refcnt
in this global list.

Close this race condition by checking if refcnt is zero
or not in llc_sap_find(), if it is zero then it is being
removed so we can just treat it as gone.

Reported-by: <syzbot+278893f3f7803871f7ce@syzkaller.appspotmail.com>
Signed-off-by: Cong Wang <xiyou.wangcong@gmail.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
include/net/llc.h
net/llc/llc_core.c