From mboxrd@z Thu Jan 1 00:00:00 1970 From: Maxime Coquelin Subject: Re: [PATCH] vhost: fix possible null pointer dereferencing Date: Tue, 27 Nov 2018 10:52:00 +0100 Message-ID: <79b2ea77-302d-9ca4-491f-408de32eeb29@redhat.com> References: <20181127092325.25758-1-maxime.coquelin@redhat.com> <20181127094409.GA20896@debian> Mime-Version: 1.0 Content-Type: text/plain; charset=utf-8; format=flowed Content-Transfer-Encoding: 7bit Cc: dev@dpdk.org, zhihong.wang@intel.com, jfreimann@redhat.com, stable@dpdk.org To: Tiwei Bie Return-path: In-Reply-To: <20181127094409.GA20896@debian> Content-Language: en-US List-Id: DPDK patches and discussions List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: dev-bounces@dpdk.org Sender: "dev" On 11/27/18 10:44 AM, Tiwei Bie wrote: > On Tue, Nov 27, 2018 at 10:23:25AM +0100, Maxime Coquelin wrote: >> If mmap() call fails in vhost_user_set_mem_table, dev->mem >> is set to NULL. If later, qva_to_vva() is called, a segfault >> occurs. >> >> Fixes: 8f972312b8f4 ("vhost: support vhost-user") >> Cc: stable@dpdk.org >> >> Signed-off-by: Maxime Coquelin >> --- >> lib/librte_vhost/vhost_user.c | 3 +++ >> 1 file changed, 3 insertions(+) >> >> diff --git a/lib/librte_vhost/vhost_user.c b/lib/librte_vhost/vhost_user.c >> index 3ea64eba6..c44fef9cc 100644 >> --- a/lib/librte_vhost/vhost_user.c >> +++ b/lib/librte_vhost/vhost_user.c >> @@ -489,6 +489,9 @@ qva_to_vva(struct virtio_net *dev, uint64_t qva, uint64_t *len) >> struct rte_vhost_mem_region *r; >> uint32_t i; >> >> + if (unlikely(!dev || !dev->mem)) >> + return 0; > > Better to also zero *len. > > Reviewed-by: Tiwei Bie Right, I'll post a v2 zeroing *len. Thanks, Maxime > >> + >> /* Find the region where the address lives. */ >> for (i = 0; i < dev->mem->nregions; i++) { >> r = &dev->mem->regions[i]; >> -- >> 2.17.2 >>