]> git.baikalelectronics.ru Git - kernel.git/commit
virtio_pci: fix use after free on release
authorMichael S. Tsirkin <mst@redhat.com>
Thu, 14 Jan 2016 14:00:41 +0000 (16:00 +0200)
committerMichael S. Tsirkin <mst@redhat.com>
Tue, 26 Jan 2016 08:18:28 +0000 (10:18 +0200)
commit39e179c55b906cca499b903f76caf7a9180f5fa7
tree91fc1b8002e4c9868d0e692dd6b4039e965c9a36
parent5367e65a538f2d59834d845f582bc1f1ae9599b8
virtio_pci: fix use after free on release

KASan detected a use-after-free error in virtio-pci remove code. In
virtio_pci_remove(), vp_dev is still used after being freed in
unregister_virtio_device() (in virtio_pci_release_dev() more
precisely).

To fix, keep a reference until cleanup is done.

Fixes: c19194d96747 ("virtio_pci: defer kfree until release callback")
Reported-by: Jerome Marchand <jmarchan@redhat.com>
Cc: stable@vger.kernel.org
Cc: Sasha Levin <sasha.levin@oracle.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Tested-by: Jerome Marchand <jmarchan@redhat.com>
drivers/virtio/virtio_pci_common.c