From: sashiko-bot@kernel.org
To: "Farhan Ali" <alifm@linux.ibm.com>
Cc: "Vasily Gorbik" <gor@linux.ibm.com>,
linux-s390@vger.kernel.org, "Heiko Carstens" <hca@linux.ibm.com>,
"Alexander Gordeev" <agordeev@linux.ibm.com>,
kvm@vger.kernel.org
Subject: Re: [PATCH v6 3/6] KVM: s390: pci: Fix missing error codes and memory unaccounting
Date: Thu, 23 Jul 2026 22:30:44 +0000 [thread overview]
Message-ID: <20260723223045.147021F000E9@smtp.kernel.org> (raw)
In-Reply-To: <20260723221409.5874-4-alifm@linux.ibm.com>
Thank you for your contribution! Sashiko AI review found 1 potential issue(s) to consider:
Pre-existing issues:
- [High] Concurrent execution of KVM_S390_ZPCI_OP ioctl and PCI device hot-unplug leads to Use-After-Free of zdev.
--
--- Patch [3]: [PATCH v6 3/6] KVM: s390: pci: Fix missing error codes and memory unaccounting ---
commit 1ca75882cbc64513fea8b4f11f208e8914e5eb06
Author: Farhan Ali <alifm@linux.ibm.com>
KVM: s390: pci: Fix missing error codes and memory unaccounting
In kvm_s390_pci_aif_enable() two error paths failed to set an error code,
causing the function to return 0 on failure. It also failed to rollback
memory accounting on failure. Fix both by propagating an error code on
failure and calling unaccount_mem() in the cleanup path.
> diff --git a/arch/s390/kvm/pci.c b/arch/s390/kvm/pci.c
> index 44c00e5e32c57..f58d7ec0bc7ec 100644
> --- a/arch/s390/kvm/pci.c
> +++ b/arch/s390/kvm/pci.c
[ ... ]
> @@ -351,6 +354,8 @@ static int kvm_s390_pci_aif_enable(struct zpci_dev *zdev, struct zpci_fib *fib,
> return rc;
>
> unlock:
> + if (pcount > 0)
> + unaccount_mem(zdev->kzdev, pcount);
> mutex_unlock(&aift->aift_lock);
> unpin2:
> if (fib->fmt0.sum == 1)
[Severity: High]
This is a pre-existing issue, but I noticed a potential use-after-free
involving the zdev pointer in this file.
When userspace calls the KVM_S390_ZPCI_OP ioctl, kvm_s390_pci_zpci_op()
fetches zdev from get_zdev_from_kvm_by_fh():
arch/s390/kvm/pci.c:get_zdev_from_kvm_by_fh() {
list_for_each_entry(kzdev, &kvm->arch.kzdev_list, entry) {
if (kzdev->zdev->fh == fh) {
zdev = kzdev->zdev;
break;
}
}
spin_unlock(&kvm->arch.kzdev_list_lock);
return zdev;
}
The zdev pointer is returned without taking a reference count. If the ioctl
thread is preempted, and the physical PCI device is removed concurrently
(hot-unplug), the PCI subsystem could drop the last reference to zdev and
free it via kfree_rcu().
After the RCU grace period, the ioctl thread would resume and attempt to
lock the freed memory:
arch/s390/kvm/pci.c:kvm_s390_pci_zpci_op() {
zdev = get_zdev_from_kvm_by_fh(kvm, args->fh);
if (!zdev)
return -ENODEV;
mutex_lock(&zdev->kzdev_lock);
...
}
Does this sequence allow a use-after-free if the device is removed while
the ioctl is executing?
--
Sashiko AI review · https://sashiko.dev/#/patchset/20260723221409.5874-1-alifm@linux.ibm.com?part=3
next prev parent reply other threads:[~2026-07-23 22:30 UTC|newest]
Thread overview: 16+ messages / expand[flat|nested] mbox.gz Atom feed top
2026-07-23 22:14 [PATCH v6 0/6] KVM s390x PCI fixes Farhan Ali
2026-07-23 22:14 ` [PATCH v6 1/6] KVM: s390: pci: Reject adapter interrupt forwarding if already enabled Farhan Ali
2026-07-23 22:30 ` sashiko-bot
2026-07-23 22:14 ` [PATCH v6 2/6] KVM: s390: pci: Fix memory accounting for pinned/unpinned pages Farhan Ali
2026-07-23 22:26 ` sashiko-bot
2026-07-24 2:20 ` Matthew Rosato
2026-07-23 22:14 ` [PATCH v6 3/6] KVM: s390: pci: Fix missing error codes and memory unaccounting Farhan Ali
2026-07-23 22:30 ` sashiko-bot [this message]
2026-07-23 22:14 ` [PATCH v6 4/6] KVM: s390: pci: Fix NULL dereference on AIBV allocation failure Farhan Ali
2026-07-23 22:28 ` sashiko-bot
2026-07-23 22:14 ` [PATCH v6 5/6] KVM: s390: pci: Fix resource leak on IRQ registration failure Farhan Ali
2026-07-23 22:25 ` sashiko-bot
2026-07-23 22:14 ` [PATCH v6 6/6] KVM: s390: pci: Validate AIBV and AISB before pinning guest pages Farhan Ali
2026-07-23 22:24 ` sashiko-bot
2026-07-24 2:10 ` [PATCH v6 0/6] KVM s390x PCI fixes Matthew Rosato
2026-07-24 9:36 ` Christian Borntraeger
Reply instructions:
You may reply publicly to this message via plain-text email
using any one of the following methods:
* Save the following mbox file, import it into your mail client,
and reply-to-all from there: mbox
Avoid top-posting and favor interleaved quoting:
https://en.wikipedia.org/wiki/Posting_style#Interleaved_style
* Reply using the --to, --cc, and --in-reply-to
switches of git-send-email(1):
git send-email \
--in-reply-to=20260723223045.147021F000E9@smtp.kernel.org \
--to=sashiko-bot@kernel.org \
--cc=agordeev@linux.ibm.com \
--cc=alifm@linux.ibm.com \
--cc=gor@linux.ibm.com \
--cc=hca@linux.ibm.com \
--cc=kvm@vger.kernel.org \
--cc=linux-s390@vger.kernel.org \
--cc=sashiko-reviews@lists.linux.dev \
/path/to/YOUR_REPLY
https://kernel.org/pub/software/scm/git/docs/git-send-email.html
* If your mail client supports setting the In-Reply-To header
via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line
before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox