From mboxrd@z Thu Jan 1 00:00:00 1970 From: Rusty Russell Subject: Re: [PATCH] virtio-pci: fix use after free Date: Tue, 08 Nov 2011 20:49:27 +1030 Message-ID: <87y5vqrk5s.fsf@rustcorp.com.au> References: <20111107163703.GA10358@redhat.com> <20111108054616.GC2068@amit-x200.redhat.com> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Return-path: In-Reply-To: <20111108054616.GC2068@amit-x200.redhat.com> List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Sender: virtualization-bounces@lists.linux-foundation.org Errors-To: virtualization-bounces@lists.linux-foundation.org To: Amit Shah , "Michael S. Tsirkin" Cc: stable@kernel.org, linux-kernel@vger.kernel.org, virtualization@lists.linux-foundation.org List-Id: virtualization@lists.linuxfoundation.org On Tue, 8 Nov 2011 11:16:16 +0530, Amit Shah wrote: > On (Mon) 07 Nov 2011 [18:37:05], Michael S. Tsirkin wrote: > > Commit 31a3ddda166cda86d2b5111e09ba4bda5239fae6 introduced > > a use after free in virtio-pci. The main issue is > > that the release method signals removal of the virtio device, > > while remove signals removal of the pci device. > > > > For example, on driver removal or hot-unplug, > > virtio_pci_release_dev is called before virtio_pci_remove. > > We then might get a crash as virtio_pci_remove tries to use the > > device freed by virtio_pci_release_dev. > > > > We allocate/free all resources together with the > > pci device, so we can leave the release method empty. > > > > Signed-off-by: Michael S. Tsirkin > > Acked-by: Amit Shah > > (note: Adding CC: stable@kernel.org to the commit log is the way > patches get automatically pulled from upstream when committed; CC'ing > stable on submissions won't help with that.) Yeah, I fixed it though. Cheers, Rusty.