Back

MEDIUM

net: fix a memleak when uncloning an skb dst and its metadata

Published Jul 16, 2024

Description

When uncloning an skb dst and its associated metadata, a new dst+metadata is allocated and later replaces the old one in the skb. This is helpful to have a non-shared dst+metadata attached to a specific skb.

The issue is the uncloned dst+metadata is initialized with a refcount of 1, which is increased to 2 before attaching it to the skb. When tun_dst_unclone returns, the dst+metadata is only referenced from a single place (the skb) while its refcount is 2. Its refcount will never drop to 0 (when the skb is consumed), leading to a memory leak.

Fix this by removing the call to dst_hold in tun_dst_unclone, as the dst+metadata refcount is already 1.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (2)

References (13)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Linux
Published Jul 16, 2024
Updated May 11, 2026
Reserved Jul 16, 2024
CISA Vulnrichment
Updated Sep 10, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jul 16, 2024