From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: X-Spam-Checker-Version: SpamAssassin 3.4.0 (2014-02-07) on aws-us-west-2-korg-lkml-1.web.codeaurora.org Received: from mails.dpdk.org (mails.dpdk.org [217.70.189.124]) by smtp.lore.kernel.org (Postfix) with ESMTP id 5F703CA5FCE for ; Mon, 5 Oct 2026 08:55:22 +0000 (UTC) Received: from mails.dpdk.org (localhost [127.0.0.1]) by mails.dpdk.org (Postfix) with ESMTP id C940340E2E; Mon, 5 Oct 2026 10:54:01 +0200 (CEST) Received: from inva020.nxp.com (inva020.nxp.com [92.121.34.13]) by mails.dpdk.org (Postfix) with ESMTP id 669D840A81; Mon, 5 Oct 2026 10:53:46 +0200 (CEST) Received: from inva020.nxp.com (localhost [127.0.0.1]) by inva020.eu-rdc02.nxp.com (Postfix) with ESMTP id 4A37F1A007E; Mon, 5 Oct 2026 10:53:46 +0200 (CEST) Received: from aprdc01srsp001v.ap-rdc01.nxp.com (aprdc01srsp001v.ap-rdc01.nxp.com [165.114.16.16]) by inva020.eu-rdc02.nxp.com (Postfix) with ESMTP id 14C991A007A; Mon, 5 Oct 2026 10:53:46 +0200 (CEST) Received: from lsv03583.swis.in-blr01.nxp.com (lsv03583.swis.in-blr01.nxp.com [92.120.146.12]) by aprdc01srsp001v.ap-rdc01.nxp.com (Postfix) with ESMTP id 7E9601800226; Mon, 5 Oct 2026 16:53:45 +0800 (+08) From: Hemant Agrawal To: stephen@networkplumber.org, thomas@monjalon.net, dev@dpdk.org Cc: stable@dpdk.org Subject: [PATCH v20 16/27] mempool/dpaa: fix write after free on pool free Date: Mon, 5 Oct 2026 14:23:26 +0530 Message-Id: <20261005085337.1069213-17-hemant.agrawal@nxp.com> X-Mailer: git-send-email 2.25.1 In-Reply-To: <20261005085337.1069213-1-hemant.agrawal@nxp.com> References: <20261001112430.251845-1-hemant.agrawal@nxp.com> <20261005085337.1069213-1-hemant.agrawal@nxp.com> MIME-Version: 1.0 Content-Transfer-Encoding: 8bit X-Virus-Scanned: ClamAV using ClamSMTP X-BeenThere: dev@dpdk.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: DPDK patches and discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dev-bounces@dpdk.org dpaa_mbuf_free_pool() freed the pool private data and then wrote to it: rte_free(mp->pool_data); bp_info->bp = NULL; bp_info is DPAA_MEMPOOL_TO_POOL_INFO(mp), which is mp->pool_data, so both refer to the same allocation. Clearing bp_info->bp after the rte_free() writes into freed memory. Clear the field before releasing the allocation, and free bp_info directly rather than the alias. Fixes: 376fb49ecfca ("net/dpaa: prevent multiple mempool config") Cc: stable@dpdk.org Signed-off-by: Hemant Agrawal --- drivers/mempool/dpaa/dpaa_mempool.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/drivers/mempool/dpaa/dpaa_mempool.c b/drivers/mempool/dpaa/dpaa_mempool.c index 2f8555a026..94aea5e77c 100644 --- a/drivers/mempool/dpaa/dpaa_mempool.c +++ b/drivers/mempool/dpaa/dpaa_mempool.c @@ -143,8 +143,8 @@ dpaa_mbuf_free_pool(struct rte_mempool *mp) bman_free_pool(bp_info->bp); DPAA_MEMPOOL_INFO("BMAN pool freed for bpid =%d", bp_info->bpid); - rte_free(mp->pool_data); bp_info->bp = NULL; + rte_free(bp_info); mp->pool_data = NULL; } } -- 2.25.1