Re: [PATCH net] net/dibs: Correct freeing of dmb_clientid_arr

Dust Li <[email protected]>
Newsgroups org.kernel.vger.stable,org.kernel.vger.linux-kernel,org.kernel.vger.linux-s390,org.kernel.vger.netdev
Message-ID <[email protected]>
On 2026-08-10 13:14:32, Alexandra Winter wrote:
>A dibs device interrupt handler can be active after dibs_dev_del() and
>may still access dmb_clientid_arr. (UAF)
>
>In case of a failure in dibs_dev_add() being called by dibs_lo_dev_probe()
>dmb_clientid_arr is freed twice (double free).
>
>Free dmb_clientid_arr in dibs_dev_release() after last reference is gone.
>Note that allocating in dibs_dev_add() instead of dibs_dev_alloc() is ok
>for now, because no dmbs can be registered before dibs_dev_add().
>
>Fixes: cc21191b584c ("dibs: Move data path to dibs layer")
>Cc: [email protected]
>Co-developed-by: Hidayath Khan <[email protected]>
>Signed-off-by: Hidayath Khan <[email protected]>
>Signed-off-by: Alexandra Winter <[email protected]>

Reviewed-by: Dust Li <[email protected]>

Best regards,
Dust
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.