diff options
| author | Zhenlei Huang <zlei@FreeBSD.org> | 2026-03-16 16:20:08 +0000 |
|---|---|---|
| committer | Zhenlei Huang <zlei@FreeBSD.org> | 2026-03-20 10:02:19 +0000 |
| commit | 47339e4a9209c1d1323f58d792e277792990e060 (patch) | |
| tree | 233bc47cd656add71091c3c02f75bb1b8b0b28e9 | |
| parent | fa5f0d95be25f670f9752e4785f55cbdeb830bab (diff) | |
ifnet: Fix decreasing the vnet interface count
It should be decreased only when the interface has been successfully
removed from the "active" list.
This prevents vnet_if_return() from potential OOB writes to the
allocated memory "pending".
Reviewed by: kp, pouria
Fixes: a779388f8bb3 if: Protect V_ifnet in vnet_if_return()
MFC after: 3 days
Differential Revision: https://reviews.freebsd.org/D55873
(cherry picked from commit 8065ff63c0e5c3bb4abb02f55b20cb47bb51d1a7)
(cherry picked from commit 1b7687f053afcf251ee7643ee5a4f22a225f4a02)
| -rw-r--r-- | sys/net/if.c | 6 |
1 files changed, 3 insertions, 3 deletions
diff --git a/sys/net/if.c b/sys/net/if.c index 0c7e32e858bc..44f80a51eea8 100644 --- a/sys/net/if.c +++ b/sys/net/if.c @@ -459,14 +459,14 @@ if_unlink_ifnet(struct ifnet *ifp, bool vmove) CK_STAILQ_FOREACH(iter, &V_ifnet, if_link) if (iter == ifp) { CK_STAILQ_REMOVE(&V_ifnet, ifp, ifnet, if_link); +#ifdef VIMAGE + curvnet->vnet_ifcnt--; +#endif if (!vmove) ifp->if_flags |= IFF_DYING; found = 1; break; } -#ifdef VIMAGE - curvnet->vnet_ifcnt--; -#endif IFNET_WUNLOCK(); return (found); |
