Re: [PATCH net] ipip: fix skb leak in collect_md mode when metadata_dst allocation fails

From: patchwork-bot+netdevbpf

Date: Sat Aug 22 2026 - 16:11:17 EST


Hello:

This patch was applied to netdev/net.git (main)
by Jakub Kicinski <kuba@xxxxxxxxxx>:

On Wed, 19 Aug 2026 13:43:39 +0300 you wrote:
> In collect_md mode ipip_tunnel_rcv() returns 0 without freeing the skb
> when ip_tun_rx_dst() fails to allocate the metadata_dst. ipip_rcv() and
> mplsip_rcv() are registered as xfrm_tunnel handlers, so tunnel4_rcv()
> and tunnelmpls4_rcv() read the zero return as "the packet has been
> consumed" and do not free it either. The skb is leaked.
>
> The other tunnel drivers all dispose of the packet at this point:
> ip6_tunnel.c jumps to its drop label, ip_gre.c and ip6_gre.c return
> PACKET_REJECT, which makes gre_rcv() free the skb. Only ipip returns 0.
>
> [...]

Here is the summary with links:
- [net] ipip: fix skb leak in collect_md mode when metadata_dst allocation fails
https://git.kernel.org/netdev/net/c/6776efe4a52f

You are awesome, thank you!
--
Deet-doot-dot, I am a bot.
https://korg.docs.kernel.org/patchwork/pwbot.html