Re: [Linux-kernel-mentees] [PATCH v3 net] rose: Fix Null pointer dereference in rose_send_frame()

From: Jakub Kicinski
Date: Tue Nov 10 2020 - 12:58:21 EST


On Sun, 8 Nov 2020 00:48:35 +0530 Anmol Karn wrote:
> + dev = rose_dev_get(dest);

this calls dev_hold internally, you never release that reference in
case ..neigh->dev is NULL

> + if (rose_loopback_neigh->dev && dev) {