]> www.infradead.org Git - users/jedix/linux-maple.git/commit
ipv4: Don't do expensive useless work during inetdev destroy.
authorDavid S. Miller <davem@davemloft.net>
Mon, 14 Mar 2016 03:28:00 +0000 (23:28 -0400)
committerChuck Anderson <chuck.anderson@oracle.com>
Thu, 14 Apr 2016 00:22:56 +0000 (17:22 -0700)
commit25fb195f952bfc3d9fd2c4aa45f8522f12a83b8f
tree523efba9b75662daf0fc97ccc05087d31e1c1c04
parentf36867a43dcb132a1655c51f945b1bdd714f0eee
ipv4: Don't do expensive useless work during inetdev destroy.

When an inetdev is destroyed, every address assigned to the interface
is removed.  And in this scenerio we do two pointless things which can
be very expensive if the number of assigned interfaces is large:

1) Address promotion.  We are deleting all addresses, so there is no
   point in doing this.

2) A full nf conntrack table purge for every address.  We only need to
   do this once, as is already caught by the existing
   masq_dev_notifier so masq_inet_event() can skip this.

Reported-by: Solar Designer <solar@openwall.com>
Signed-off-by: David S. Miller <davem@davemloft.net>
Tested-by: Cyrill Gorcunov <gorcunov@openvz.org>
(cherry picked from commit fbd40ea0180a2d328c5adc61414dc8bab9335ce2)

Orabug: 22933004
CVE: CVE-2016-3156
Signed-off-by: Manjunath Govindashetty <manjunath.govindashetty@oracle.com>
net/ipv4/devinet.c
net/ipv4/fib_frontend.c
net/ipv4/netfilter/nf_nat_masquerade_ipv4.c