bridge: vlan: Prevent possible use-after-free
authorIdo Schimmel <idosch@mellanox.com>
Fri, 30 Oct 2015 16:46:19 +0000 (17:46 +0100)
committerDavid S. Miller <davem@davemloft.net>
Mon, 2 Nov 2015 20:40:10 +0000 (15:40 -0500)
commit07bc588fc1087929e8e6dfe95ffcee1cb69a240f
treeb07f5e0dc59c8e79d128eb5b6be5725cb610fedd
parentce1050089c969b96c797118f9cb0cf5a421ddc69
bridge: vlan: Prevent possible use-after-free

When adding a port to a bridge we initialize VLAN filtering on it. We do
not bail out in case an error occurred in nbp_vlan_init, as it can be
used as a non VLAN filtering bridge.

However, if VLAN filtering is required and an error occurred in
nbp_vlan_init, we should set vlgrp to NULL, so that VLAN filtering
functions (e.g. br_vlan_find, br_get_pvid) will know the struct is
invalid and will not try to access it.

Signed-off-by: Ido Schimmel <idosch@mellanox.com>
Signed-off-by: Nikolay Aleksandrov <nikolay@cumulusnetworks.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
net/bridge/br_vlan.c