summaryrefslogtreecommitdiff
path: root/net/core
diff options
context:
space:
mode:
authorweichenchen <weichen.chen@linux.alibaba.com>2020-12-25 13:44:45 +0800
committerDavid S. Miller <davem@davemloft.net>2020-12-28 14:49:48 -0800
commita533b70a657c03137dd49cbcfee70aac086ab2b1 (patch)
treeec36cd2b1aaea81ad270c0bb939a083d8a47829a /net/core
parent21fdca22eb7df2a1e194b8adb812ce370748b733 (diff)
downloadlwn-a533b70a657c03137dd49cbcfee70aac086ab2b1.tar.gz
lwn-a533b70a657c03137dd49cbcfee70aac086ab2b1.zip
net: neighbor: fix a crash caused by mod zero
pneigh_enqueue() tries to obtain a random delay by mod NEIGH_VAR(p, PROXY_DELAY). However, NEIGH_VAR(p, PROXY_DELAY) migth be zero at that point because someone could write zero to /proc/sys/net/ipv4/neigh/[device]/proxy_delay after the callers check it. This patch uses prandom_u32_max() to get a random delay instead which avoids potential division by zero. Signed-off-by: weichenchen <weichen.chen@linux.alibaba.com> Signed-off-by: David S. Miller <davem@davemloft.net>
Diffstat (limited to 'net/core')
-rw-r--r--net/core/neighbour.c6
1 files changed, 2 insertions, 4 deletions
diff --git a/net/core/neighbour.c b/net/core/neighbour.c
index 9500d28a43b0..277ed854aef1 100644
--- a/net/core/neighbour.c
+++ b/net/core/neighbour.c
@@ -1569,10 +1569,8 @@ static void neigh_proxy_process(struct timer_list *t)
void pneigh_enqueue(struct neigh_table *tbl, struct neigh_parms *p,
struct sk_buff *skb)
{
- unsigned long now = jiffies;
-
- unsigned long sched_next = now + (prandom_u32() %
- NEIGH_VAR(p, PROXY_DELAY));
+ unsigned long sched_next = jiffies +
+ prandom_u32_max(NEIGH_VAR(p, PROXY_DELAY));
if (tbl->proxy_queue.qlen > NEIGH_VAR(p, PROXY_QLEN)) {
kfree_skb(skb);