From 09bdee7713c32498a2d260e38104467be98bd88a Mon Sep 17 00:00:00 2001 From: Jiuzhu Dong Date: Tue, 13 Apr 2021 17:00:59 +0800 Subject: [PATCH] net/arp: Fix memory corruption in arp_send() Summary: - In arp_send(), arp_wait_setup() adds a notify object to g_arp_waiters which is removed in arp_wait() in normal case. - However, in timeout and error cases, the object was not removed and caused memory corruption. - This commit fixes this issue. Impact: - None Testing: - Tested with spresense:rndis_smp Change-Id: I55e56661b7ff665171805af9106f3a04cc2c3cad Signed-off-by: Jiuzhu Dong --- net/arp/arp_send.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/net/arp/arp_send.c b/net/arp/arp_send.c index 17dc1451b6b..4a2c3e4aa74 100644 --- a/net/arp/arp_send.c +++ b/net/arp/arp_send.c @@ -341,6 +341,7 @@ int arp_send(in_addr_t ipaddr) CONFIG_ARP_SEND_DELAYMSEC); if (ret == -ETIMEDOUT) { + arp_wait_cancel(¬ify); goto timeout; } } @@ -354,6 +355,7 @@ int arp_send(in_addr_t ipaddr) /* Break out on a send failure */ nerr("ERROR: Send failed: %d\n", ret); + arp_wait_cancel(¬ify); break; }