Re: [PATCH v2] virtio_console: fix a crash in config_work_handler

From: Michael S. Tsirkin
Date: Mon Jan 16 2017 - 08:31:18 EST


On Mon, Jan 16, 2017 at 03:57:23PM +0530, Amit Shah wrote:
> On (Mon) 16 Jan 2017 [10:45:02], G. Campana wrote:
> > Using control_work instead of config_work as the 3rd argument to
> > container_of results in an invalid portdev pointer. Indeed, the work
> > structure is initialized as below:
> >
> > INIT_WORK(&portdev->config_work, &config_work_handler);
> >
> > It leads to a crash when portdev->vdev is dereferenced later. This bug
> > is triggered when the guest uses a virtio-console without multiport
> > feature and receives a config_changed virtio interrupt.
> >
> > Signed-off-by: G. Campana <gcampana@xxxxxxxxxxxxx>
>
> Reviewed-by: Amit Shah <amit.shah@xxxxxxxxxx>
>
> Michael, can you please pick this up?
>
> Amit

Sure.