diff options
author | Dan Carpenter <[email protected]> | 2020-12-04 17:23:36 +0300 |
---|---|---|
committer | Michael S. Tsirkin <[email protected]> | 2020-12-18 16:14:31 -0500 |
commit | e152d8af4220a05c9797591609151d404866beaa (patch) | |
tree | 743cd19be076a1bd787c3202dd611e86553843e9 /scripts/gdb/linux/device.py | |
parent | 411ea23a76526e6efed0b601abb603d3c981b333 (diff) |
virtio_ring: Fix two use after free bugs
The "vq" struct is added to the "vdev->vqs" list prematurely. If we
encounter an error later in the function then the "vq" is freed, but
since it is still on the list that could lead to a use after free bug.
Fixes: cbeedb72b97a ("virtio_ring: allocate desc state for split ring separately")
Reported-by: Robert Buhren <[email protected]>
Reported-by: Felicitas Hetzelt <[email protected]>
Signed-off-by: Dan Carpenter <[email protected]>
Link: https://lore.kernel.org/r/X8pGaG/zkI3jk8mk@mwanda
Signed-off-by: Michael S. Tsirkin <[email protected]>
Acked-by: Jason Wang <[email protected]>
Diffstat (limited to 'scripts/gdb/linux/device.py')
0 files changed, 0 insertions, 0 deletions