Re: [Intel-wired-lan] [PATCH iwl-net v1] ice: fix use-after-free in dynamic port cleanup

"Loktionov, Aleksandr" <[email protected]> Tue, 14 Jul 2026 14:24:17 +0000
Newsgroups org.osuosl.intel-wired-lan,org.kernel.vger.netdev,org.kernel.vger.stable
Message-ID <IA3PR11MB89860941F0C6CEDC9FE676F7E5F92@IA3PR11MB8986.namprd11.prod.outlook.com>

> -----Original Message-----
> From: Intel-wired-lan <[email protected]> On Behalf
> Of [email protected]
> Sent: Tuesday, July 14, 2026 8:40 AM
> To: [email protected]
> Cc: Nguyen, Anthony L <[email protected]>; Kitszel,
> Przemyslaw <[email protected]>; [email protected];
> Samudrala, Sridhar <[email protected]>; Drewek, Wojciech
> <[email protected]>; [email protected];
> [email protected]; Keller, Jacob E
> <[email protected]>; [email protected]; Xuanqiang Luo
> <[email protected]>; [email protected]
> Subject: [Intel-wired-lan] [PATCH iwl-net v1] ice: fix use-after-free
> in dynamic port cleanup
> 
> From: Xuanqiang Luo <[email protected]>
> 
> ice_dealloc_dynamic_port() uses dyn_port->vsi->idx to erase the
> dynamic port from pf->dyn_ports. However, it frees the VSI before
> reading the index for the erase, resulting in a use-after-free.
> 
> Follow the reverse of the allocation order in ice_alloc_dynamic_port()
> by erasing the xarray entry before freeing the VSI.
> 
> Fixes: eda69d654c7e ("ice: add basic devlink subfunctions support")
> Cc: [email protected]
> Signed-off-by: Xuanqiang Luo <[email protected]>
> ---
>  drivers/net/ethernet/intel/ice/devlink/port.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/net/ethernet/intel/ice/devlink/port.c
> b/drivers/net/ethernet/intel/ice/devlink/port.c
> index 2a2e56777f9f7..3ede246490027 100644
> --- a/drivers/net/ethernet/intel/ice/devlink/port.c
> +++ b/drivers/net/ethernet/intel/ice/devlink/port.c
> @@ -590,8 +590,8 @@ static void ice_dealloc_dynamic_port(struct
> ice_dynamic_port *dyn_port)
> 
>  	xa_erase(&pf->sf_nums, devlink_port->attrs.pci_sf.sf);
>  	ice_eswitch_detach_sf(pf, dyn_port);
> -	ice_vsi_free(dyn_port->vsi);
>  	xa_erase(&pf->dyn_ports, dyn_port->vsi->idx);
> +	ice_vsi_free(dyn_port->vsi);
>  	kfree(dyn_port);
>  }
> 
> --
> 2.43.0


Reviewed-by: Aleksandr Loktionov <[email protected]>