Re: [PATCH 16/16] virtio_net: fix use after free on allocation failure

From: Cornelia Huck
Date: Mon Oct 06 2014 - 10:17:42 EST


On Sun, 5 Oct 2014 19:07:38 +0300
"Michael S. Tsirkin" <mst@xxxxxxxxxx> wrote:

> In the extremely unlikely event that driver initialization fails after
> RX buffers are added, virtio net frees RX buffers while VQs are
> still active, potentially causing device to use a freed buffer.
>
> To fix, reset device first - same as we do on device removal.
>
> Signed-off-by: Michael S. Tsirkin <mst@xxxxxxxxxx>
> ---
> drivers/net/virtio_net.c | 2 ++
> 1 file changed, 2 insertions(+)

Reviewed-by: Cornelia Huck <cornelia.huck@xxxxxxxxxx>

--
To unsubscribe from this list: send the line "unsubscribe linux-kernel" in
the body of a message to majordomo@xxxxxxxxxxxxxxx
More majordomo info at http://vger.kernel.org/majordomo-info.html
Please read the FAQ at http://www.tux.org/lkml/