Hi there,

On 07/08/2026 08:48, Qingshuang Fu wrote:
From: Qingshuang Fu <[email protected]>

The ovpn_socket() function creates a socket but fails to close it on
several error paths, leading to a file descriptor leak:

1. When the address family is neither AF_INET nor AF_INET6, the socket
    is leaked in the switch default case.
2. When setsockopt() for SO_REUSEADDR, SO_REUSEPORT, or SO_MARK fails,
    the socket is leaked.
3. When setsockopt() for IPV6_V6ONLY fails, the socket is leaked.

The existing err_socket label already handles closing the socket for
the bind() failure path. Fix all other error paths to use goto
err_socket instead of returning directly, ensuring the socket is
properly closed on every error path.

Fixes: 959bc330a439 ("testing/selftests: add test tool and scripts for ovpn 
module")

We'd rather send changes like this to net-next, so no Fixes tag required.

Signed-off-by: Qingshuang Fu <[email protected]>

This said, we already have a patch reworking this part of the selftest with, which is also addressing this issue:

https://patchwork.openvpn.net/project/ovpn/patch/[email protected]/

It is pending to be sent to net-next as soon as we're finished with the fixes in our pipe.

Thanks for your contribution in any case!


Regards,



--
Antonio Quartulli
OpenVPN Inc.


Reply via email to