From: Stephen Hemminger <stephen@networkplumber.org>
To: dev@dpdk.org
Cc: Stephen Hemminger <stephen@networkplumber.org>,
stable@dpdk.org,
Kishore Padmanabha <kishore.padmanabha@broadcom.com>,
Ajit Khaparde <ajit.khaparde@broadcom.com>
Subject: [PATCH 1/6] net/bnxt: fix use after free when freeing filters
Date: Thu, 17 Sep 2026 10:19:39 -0700 [thread overview]
Message-ID: <20260917172116.660120-2-stephen@networkplumber.org> (raw)
In-Reply-To: <20260917172116.660120-1-stephen@networkplumber.org>
bnxt_free_filter_mem() freed each filter and then passed the freed
pointer to STAILQ_REMOVE, which walks the list to unlink it.
STAILQ_FOREACH also read the next pointer out of the freed element.
Remove the entry from the list before freeing it, and use
STAILQ_FOREACH_SAFE so that the iteration does not depend on the
element that was just freed. glibc does not provide the _SAFE
variants, so define it locally the same way several other drivers
already do.
Found while moving the list macros into a DPDK header, where the
compiler could see them and report -Wuse-after-free. The fix does
not depend on that work.
Fixes: f11fd694a84a ("net/bnxt: free memory allocated for VF filters")
Cc: stable@dpdk.org
Signed-off-by: Stephen Hemminger <stephen@networkplumber.org>
---
drivers/net/bnxt/bnxt_filter.c | 14 +++++++++++---
1 file changed, 11 insertions(+), 3 deletions(-)
diff --git a/drivers/net/bnxt/bnxt_filter.c b/drivers/net/bnxt/bnxt_filter.c
index 7b90ba651f..0225215dae 100644
--- a/drivers/net/bnxt/bnxt_filter.c
+++ b/drivers/net/bnxt/bnxt_filter.c
@@ -18,6 +18,13 @@
#include "bnxt_vnic.h"
#include "hsi_struct_def_dpdk.h"
+#ifndef STAILQ_FOREACH_SAFE
+#define STAILQ_FOREACH_SAFE(var, head, field, tvar) \
+ for ((var) = STAILQ_FIRST((head)); \
+ (var) && ((tvar) = STAILQ_NEXT((var), field), 1); \
+ (var) = (tvar))
+#endif
+
/*
* Filter Functions
*/
@@ -110,7 +117,7 @@ void bnxt_free_all_filters(struct bnxt *bp)
void bnxt_free_filter_mem(struct bnxt *bp)
{
- struct bnxt_filter_info *filter;
+ struct bnxt_filter_info *filter, *temp_filter;
uint16_t max_filters, i;
int rc = 0;
@@ -151,10 +158,11 @@ void bnxt_free_filter_mem(struct bnxt *bp)
bp->filter_info = NULL;
for (i = 0; i < bp->pf->max_vfs; i++) {
- STAILQ_FOREACH(filter, &bp->pf->vf_info[i].filter, next) {
- rte_free(filter);
+ STAILQ_FOREACH_SAFE(filter, &bp->pf->vf_info[i].filter, next,
+ temp_filter) {
STAILQ_REMOVE(&bp->pf->vf_info[i].filter, filter,
bnxt_filter_info, next);
+ rte_free(filter);
}
}
}
--
2.53.0
next prev parent reply other threads:[~2026-09-17 17:21 UTC|newest]
Thread overview: 9+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-09-17 17:19 [PATCH 0/6] provide a complete set of BSD list macros Stephen Hemminger
2026-09-17 17:19 ` Stephen Hemminger [this message]
2026-09-17 17:19 ` [PATCH 2/6] eal: add rte_queue.h with full set of " Stephen Hemminger
2026-09-17 17:19 ` [PATCH 3/6] build: use rte_queue.h instead of sys/queue.h Stephen Hemminger
2026-09-17 17:19 ` [PATCH 4/6] build: remove private FOREACH_SAFE definitions Stephen Hemminger
2026-09-17 17:19 ` [PATCH 5/6] eal: deprecate RTE_TAILQ and RTE_STAILQ macro wrappers Stephen Hemminger
2026-09-17 17:19 ` [PATCH 6/6] devtools: forbid direct use of sys/queue.h Stephen Hemminger
2026-09-18 11:34 ` [PATCH 0/6] provide a complete set of BSD list macros Marat Khalili
2026-09-18 11:50 ` Bruce Richardson
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260917172116.660120-2-stephen@networkplumber.org \
--to=stephen@networkplumber.org \
--cc=ajit.khaparde@broadcom.com \
--cc=dev@dpdk.org \
--cc=kishore.padmanabha@broadcom.com \
--cc=stable@dpdk.org \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox