From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from smtp.kernel.org (aws-us-west-2-korg-mail-alma10-1.taild15c8.ts.net [100.103.45.18]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by smtp.subspace.kernel.org (Postfix) with ESMTPS id A90E04E4C52; Thu, 17 Sep 2026 15:41:33 +0000 (UTC) Authentication-Results: smtp.subspace.kernel.org; arc=none smtp.client-ip=100.103.45.18 ARC-Seal:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789659707; cv=none; b=dHbrXm3moAs4MIvKv8Xd3TD2mZhPoIEQsgeEIrtz43YlLISNFVf0CrJO9GPHqdnoLpU7gSHdS4oXW+K4KygthHE8/2uxlShj4MKlJUuw004FL5MipxLZhJ2UIpfYVZb33LlNCauogARwzs5HfcUQZx0/zapfGLFYth2Yu9C5uxk= ARC-Message-Signature:i=1; a=rsa-sha256; d=subspace.kernel.org; s=arc-20240116; t=1789659707; c=relaxed/simple; bh=+obi0VAijlr/dbdupErzBzYMqiH+yd367IDO4rJ/scY=; h=From:To:Cc:Subject:Date:Message-ID:In-Reply-To:References: MIME-Version; b=V0BZqFCh34tSOJLfOkMfcOZR0zjLxw3rf9Wva87Wlabuc6k8+MHXiUIH2Xzfqs5aIK9S1ujAMPRYEagEtHhP27pwlwqegAoY7wuAwb1LJLPIa8u8ViCHKCk5ygRtVtojmCdUUZBLJxKcUW8UE4GLVqQwGuypACO6B0p4JCE+i6g= ARC-Authentication-Results:i=1; smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b=cqMCFTi3; arc=none smtp.client-ip=100.103.45.18 Authentication-Results: smtp.subspace.kernel.org; dkim=pass (1024-bit key) header.d=linuxfoundation.org header.i=@linuxfoundation.org header.b="cqMCFTi3" Received: by smtp.kernel.org (Postfix) with ESMTPSA id 2C19B1F000FF; Thu, 17 Sep 2026 15:41:33 +0000 (UTC) DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=linuxfoundation.org; s=korg; t=1789659693; bh=hl2T4DCkfUD7kz6WpLGYyJPfuzxmMJneEyhVqNohjOk=; h=From:To:Cc:Subject:Date:In-Reply-To:References; b=cqMCFTi3d7VdUFFfxurfGgfynNYw6MxVIOZf/1jIfJWAd1QxcP1OmNu1JJ5ymtwQv lkiMaKxRIhkl4xag8Aluel5oGU0D262ksr+ejYdzVqX+Znr6sdopSJqnrlAnTYQ4lS uInW+WfivoK8owr2YEqukEeDX2LyQj2Tli1+FPTI= From: Greg Kroah-Hartman To: stable@vger.kernel.org Cc: Greg Kroah-Hartman , patches@lists.linux.dev, Jia Jia , "Michael S. Tsirkin" , Sasha Levin Subject: [PATCH 7.2 343/733] virtio_console: do not free control-out buffers on remove Date: Thu, 17 Sep 2026 16:10:51 +0100 Message-ID: <20260917151400.100805646@linuxfoundation.org> X-Mailer: git-send-email 2.55.0 In-Reply-To: <20260917151350.597953846@linuxfoundation.org> References: <20260917151350.597953846@linuxfoundation.org> User-Agent: quilt/0.69 X-stable: review X-Patchwork-Hint: ignore Precedence: bulk X-Mailing-List: patches@lists.linux.dev List-Id: List-Subscribe: List-Unsubscribe: MIME-Version: 1.0 Content-Transfer-Encoding: 8bit 7.2-stable review patch. If anyone has any objections, please let me know. ------------------ From: Jia Jia [ Upstream commit 894f98e73983f37354214a89a3a7fd35bf9e3072 ] __send_control_msg() publishes &portdev->cpkt as the control-out virtqueue cookie. remove_vqs() walks every virtqueue and passes leftover cookies to free_buf(), which treats them as struct port_buffer and reads sgpages. If a control message is still on c_ovq when the device is unbound, free_buf() reads past the ports_device object. KASAN reported slab-out-of-bounds in free_buf(): free_buf remove_vqs virtcons_remove unbind_store The object was the ports_device allocated in virtcons_probe(). Drain c_ovq without freeing. The packet lives in portdev and is released with it. Fixes: a7a69ec0d8e4 ("virtio_console: free buffers after reset") Signed-off-by: Jia Jia Signed-off-by: Michael S. Tsirkin Message-ID: <20260819021230.292696-1-physicalmtea@gmail.com> Signed-off-by: Sasha Levin --- drivers/char/virtio_console.c | 21 ++++++++++++++++++--- 1 file changed, 18 insertions(+), 3 deletions(-) diff --git a/drivers/char/virtio_console.c b/drivers/char/virtio_console.c index 198b973141680..1ec5b25d1a9ae 100644 --- a/drivers/char/virtio_console.c +++ b/drivers/char/virtio_console.c @@ -1891,13 +1891,28 @@ static const struct file_operations portdev_fops = { static void remove_vqs(struct ports_device *portdev) { struct virtqueue *vq; + bool multiport = use_multiport(portdev); virtio_device_for_each_vq(portdev->vdev, vq) { struct port_buffer *buf; + unsigned int len; - flush_bufs(vq, true); - while ((buf = virtqueue_detach_unused_buf(vq))) - free_buf(buf, true); + /* + * c_ovq cookies are &portdev->cpkt, not port_buffer. + * Detach them but do not free_buf(). + */ + if (multiport && vq == portdev->c_ovq) { + spin_lock(&portdev->c_ovq_lock); + while (virtqueue_get_buf(vq, &len)) + ; + while (virtqueue_detach_unused_buf(vq)) + ; + spin_unlock(&portdev->c_ovq_lock); + } else { + flush_bufs(vq, true); + while ((buf = virtqueue_detach_unused_buf(vq))) + free_buf(buf, true); + } cond_resched(); } portdev->vdev->config->del_vqs(portdev->vdev); -- 2.53.0