All of lore.kernel.org
 help / color / mirror / Atom feed
From: sashiko-bot@kernel.org
To: "Farhan Ali" <alifm@linux.ibm.com>
Cc: "Vasily Gorbik" <gor@linux.ibm.com>,
	linux-s390@vger.kernel.org, "Heiko Carstens" <hca@linux.ibm.com>,
	"Alexander Gordeev" <agordeev@linux.ibm.com>,
	kvm@vger.kernel.org
Subject: Re: [PATCH v6 3/6] KVM: s390: pci: Fix missing error codes and memory unaccounting
Date: Thu, 23 Jul 2026 22:30:44 +0000	[thread overview]
Message-ID: <20260723223045.147021F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260723221409.5874-4-alifm@linux.ibm.com>

Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:

Pre-existing issues:
- [High] Concurrent execution of KVM_S390_ZPCI_OP ioctl and PCI device hot-unplug leads to Use-After-Free of zdev.
--

--- Patch [3]: [PATCH v6 3/6] KVM: s390: pci: Fix missing error codes and memory unaccounting ---
commit 1ca75882cbc64513fea8b4f11f208e8914e5eb06
Author: Farhan Ali <alifm@linux.ibm.com>

KVM: s390: pci: Fix missing error codes and memory unaccounting

In kvm_s390_pci_aif_enable() two error paths failed to set an error code,
causing the function to return 0 on failure. It also failed to rollback
memory accounting on failure. Fix both by propagating an error code on
failure and calling unaccount_mem() in the cleanup path.

> diff --git a/arch/s390/kvm/pci.c b/arch/s390/kvm/pci.c
> index 44c00e5e32c57..f58d7ec0bc7ec 100644
> --- a/arch/s390/kvm/pci.c
> +++ b/arch/s390/kvm/pci.c

[ ... ]

> @@ -351,6 +354,8 @@ static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
>  	return rc;
>  
>  unlock:
> +	if (pcount > 0)
> +		unaccount_mem(zdev->kzdev, pcount);
>  	mutex_unlock(&aift->aift_lock);
>  unpin2:
>  	if (fib->fmt0.sum == 1)

[Severity: High]
This is a pre-existing issue, but I noticed a potential use-after-free
involving the zdev pointer in this file.

When userspace calls the KVM_S390_ZPCI_OP ioctl, kvm_s390_pci_zpci_op()
fetches zdev from get_zdev_from_kvm_by_fh():

arch/s390/kvm/pci.c:get_zdev_from_kvm_by_fh() {
	list_for_each_entry(kzdev, &kvm->arch.kzdev_list, entry) {
		if (kzdev->zdev->fh == fh) {
			zdev = kzdev->zdev;
			break;
		}
	}
	spin_unlock(&kvm->arch.kzdev_list_lock);

	return zdev;
}

The zdev pointer is returned without taking a reference count. If the ioctl
thread is preempted, and the physical PCI device is removed concurrently
(hot-unplug), the PCI subsystem could drop the last reference to zdev and
free it via kfree_rcu().

After the RCU grace period, the ioctl thread would resume and attempt to
lock the freed memory:

arch/s390/kvm/pci.c:kvm_s390_pci_zpci_op() {
	zdev = get_zdev_from_kvm_by_fh(kvm, args->fh);
	if (!zdev)
		return -ENODEV;

	mutex_lock(&zdev->kzdev_lock);
	...
}

Does this sequence allow a use-after-free if the device is removed while
the ioctl is executing?

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260723221409.5874-1-alifm@linux.ibm.com?part=3

  reply	other threads:[~2026-07-23 22:30 UTC|newest]

Thread overview: 15+ messages / expand[flat|nested]  mbox.gz  Atom feed  top
2026-07-23 22:14 [PATCH v6 0/6] KVM s390x PCI fixes Farhan Ali
2026-07-23 22:14 ` [PATCH v6 1/6] KVM: s390: pci: Reject adapter interrupt forwarding if already enabled Farhan Ali
2026-07-23 22:30   ` sashiko-bot
2026-07-23 22:14 ` [PATCH v6 2/6] KVM: s390: pci: Fix memory accounting for pinned/unpinned pages Farhan Ali
2026-07-23 22:26   ` sashiko-bot
2026-07-24  2:20   ` Matthew Rosato
2026-07-23 22:14 ` [PATCH v6 3/6] KVM: s390: pci: Fix missing error codes and memory unaccounting Farhan Ali
2026-07-23 22:30   ` sashiko-bot [this message]
2026-07-23 22:14 ` [PATCH v6 4/6] KVM: s390: pci: Fix NULL dereference on AIBV allocation failure Farhan Ali
2026-07-23 22:28   ` sashiko-bot
2026-07-23 22:14 ` [PATCH v6 5/6] KVM: s390: pci: Fix resource leak on IRQ registration failure Farhan Ali
2026-07-23 22:25   ` sashiko-bot
2026-07-23 22:14 ` [PATCH v6 6/6] KVM: s390: pci: Validate AIBV and AISB before pinning guest pages Farhan Ali
2026-07-23 22:24   ` sashiko-bot
2026-07-24  2:10 ` [PATCH v6 0/6] KVM s390x PCI fixes Matthew Rosato

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=20260723223045.147021F000E9@smtp.kernel.org \
    --to=sashiko-bot@kernel.org \
    --cc=agordeev@linux.ibm.com \
    --cc=alifm@linux.ibm.com \
    --cc=gor@linux.ibm.com \
    --cc=hca@linux.ibm.com \
    --cc=kvm@vger.kernel.org \
    --cc=linux-s390@vger.kernel.org \
    --cc=sashiko-reviews@lists.linux.dev \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is an external index of several public inboxes,
see mirroring instructions on how to clone and mirror
all data and code used by this external index.