linux-scsi.vger.kernel.org archive mirror
 help / color / mirror / Atom feed
* [Patch v2 1/2] libiscsi: Fix use-after-free race during iscsi_session_teardown
@ 2017-07-13 16:11 Khazhismel Kumykov
       [not found] ` <20170713161122.89375-1-khazhy-hpIqsD4AKlfQT0dZR+AlfA@public.gmane.org>
  2017-08-29 18:29 ` Chris Leech
  0 siblings, 2 replies; 10+ messages in thread
From: Khazhismel Kumykov @ 2017-07-13 16:11 UTC (permalink / raw)
  To: lduncan, cleech; +Cc: linux-scsi, linux-kernel, open-iscsi, Khazhismel Kumykov

[-- Attachment #1: Type: text/plain, Size: 1398 bytes --]

Session attributes exposed through sysfs were freed before the device
was destroyed, resulting in a potential use-after-free. Free these
attributes after removing the device.

Signed-off-by: Khazhismel Kumykov <khazhy@google.com>
---
 drivers/scsi/libiscsi.c | 8 ++++----
 1 file changed, 4 insertions(+), 4 deletions(-)

diff --git a/drivers/scsi/libiscsi.c b/drivers/scsi/libiscsi.c
index 42381adf0769..8696a51a5a0c 100644
--- a/drivers/scsi/libiscsi.c
+++ b/drivers/scsi/libiscsi.c
@@ -2851,9 +2851,6 @@ EXPORT_SYMBOL_GPL(iscsi_session_setup);
 /**
  * iscsi_session_teardown - destroy session, host, and cls_session
  * @cls_session: iscsi session
- *
- * The driver must have called iscsi_remove_session before
- * calling this.
  */
 void iscsi_session_teardown(struct iscsi_cls_session *cls_session)
 {
@@ -2863,6 +2860,8 @@ void iscsi_session_teardown(struct iscsi_cls_session *cls_session)
 
 	iscsi_pool_free(&session->cmdpool);
 
+	iscsi_remove_session(cls_session);
+
 	kfree(session->password);
 	kfree(session->password_in);
 	kfree(session->username);
@@ -2877,7 +2876,8 @@ void iscsi_session_teardown(struct iscsi_cls_session *cls_session)
 	kfree(session->portal_type);
 	kfree(session->discovery_parent_type);
 
-	iscsi_destroy_session(cls_session);
+	iscsi_free_session(cls_session);
+
 	iscsi_host_dec_session_cnt(shost);
 	module_put(owner);
 }
-- 
2.13.2.932.g7449e964c-goog


[-- Attachment #2: S/MIME Cryptographic Signature --]
[-- Type: application/pkcs7-signature, Size: 4843 bytes --]

^ permalink raw reply related	[flat|nested] 10+ messages in thread

end of thread, other threads:[~2017-10-03  2:28 UTC | newest]

Thread overview: 10+ messages (download: mbox.gz follow: Atom feed
-- links below jump to the message on this page --
2017-07-13 16:11 [Patch v2 1/2] libiscsi: Fix use-after-free race during iscsi_session_teardown Khazhismel Kumykov
     [not found] ` <20170713161122.89375-1-khazhy-hpIqsD4AKlfQT0dZR+AlfA@public.gmane.org>
2017-07-13 16:11   ` [Patch v2 2/2] libiscsi: Remove iscsi_destroy_session 'Khazhismel Kumykov' via open-iscsi
     [not found]     ` <20170713161122.89375-2-khazhy-hpIqsD4AKlfQT0dZR+AlfA@public.gmane.org>
2017-08-29 18:30       ` Chris Leech
2017-09-14  0:09     ` Lee Duncan
     [not found]       ` <9be07c2e-71ef-cab4-7b04-94d33a191d03-IBi9RG/b67k@public.gmane.org>
2017-09-14  7:57         ` Johannes Thumshirn
2017-08-24 17:33   ` [Patch v2 1/2] libiscsi: Fix use-after-free race during iscsi_session_teardown 'Khazhismel Kumykov' via open-iscsi
2017-08-29 18:29 ` Chris Leech
     [not found]   ` <20170829182914.5oza32ohjj4lua6j-r8IHplWLGbA5tHQWs+pTeqPFFGjUI2lm2LY78lusg7I@public.gmane.org>
2017-08-30  1:45     ` Martin K. Petersen
     [not found]       ` <yq1r2vtzv3p.fsf-QHcLZuEGTsvQT0dZR+AlfA@public.gmane.org>
2017-09-29 22:54         ` 'Khazhismel Kumykov' via open-iscsi
     [not found]           ` <CACGdZYJ-jF8KTdHQHhmgHmFTszAUhpijby0vFA2pkysbQzeYjw-JsoAwUIsXosN+BqQ9rBEUg@public.gmane.org>
2017-10-03  2:28             ` Martin K. Petersen

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).