Re: [Intel-wired-lan] [PATCH iwl-net v1] ice: fix use-after-free in dynamic port cleanup
"Loktionov, Aleksandr" <[email protected]> Tue, 14 Jul 2026 14:24:17 +0000
| Newsgroups | org.osuosl.intel-wired-lan,org.kernel.vger.netdev,org.kernel.vger.stable |
|---|---|
| Message-ID | <IA3PR11MB89860941F0C6CEDC9FE676F7E5F92@IA3PR11MB8986.namprd11.prod.outlook.com> |
> -----Original Message----- > From: Intel-wired-lan <[email protected]> On Behalf > Of [email protected] > Sent: Tuesday, July 14, 2026 8:40 AM > To: [email protected] > Cc: Nguyen, Anthony L <[email protected]>; Kitszel, > Przemyslaw <[email protected]>; [email protected]; > Samudrala, Sridhar <[email protected]>; Drewek, Wojciech > <[email protected]>; [email protected]; > [email protected]; Keller, Jacob E > <[email protected]>; [email protected]; Xuanqiang Luo > <[email protected]>; [email protected] > Subject: [Intel-wired-lan] [PATCH iwl-net v1] ice: fix use-after-free > in dynamic port cleanup > > From: Xuanqiang Luo <[email protected]> > > ice_dealloc_dynamic_port() uses dyn_port->vsi->idx to erase the > dynamic port from pf->dyn_ports. However, it frees the VSI before > reading the index for the erase, resulting in a use-after-free. > > Follow the reverse of the allocation order in ice_alloc_dynamic_port() > by erasing the xarray entry before freeing the VSI. > > Fixes: eda69d654c7e ("ice: add basic devlink subfunctions support") > Cc: [email protected] > Signed-off-by: Xuanqiang Luo <[email protected]> > --- > drivers/net/ethernet/intel/ice/devlink/port.c | 2 +- > 1 file changed, 1 insertion(+), 1 deletion(-) > > diff --git a/drivers/net/ethernet/intel/ice/devlink/port.c > b/drivers/net/ethernet/intel/ice/devlink/port.c > index 2a2e56777f9f7..3ede246490027 100644 > --- a/drivers/net/ethernet/intel/ice/devlink/port.c > +++ b/drivers/net/ethernet/intel/ice/devlink/port.c > @@ -590,8 +590,8 @@ static void ice_dealloc_dynamic_port(struct > ice_dynamic_port *dyn_port) > > xa_erase(&pf->sf_nums, devlink_port->attrs.pci_sf.sf); > ice_eswitch_detach_sf(pf, dyn_port); > - ice_vsi_free(dyn_port->vsi); > xa_erase(&pf->dyn_ports, dyn_port->vsi->idx); > + ice_vsi_free(dyn_port->vsi); > kfree(dyn_port); > } > > -- > 2.43.0 Reviewed-by: Aleksandr Loktionov <[email protected]>