virtio_pci: fix use after free on release
authorMichael S. Tsirkin <mst@redhat.com>
Thu, 14 Jan 2016 14:00:41 +0000 (16:00 +0200)
committerMichael S. Tsirkin <mst@redhat.com>
Tue, 26 Jan 2016 08:18:28 +0000 (10:18 +0200)
commit2989be09a8a9d62a785137586ad941f916e08f83
tree91fc1b8002e4c9868d0e692dd6b4039e965c9a36
parent92e963f50fc74041b5e9e744c330dca48e04f08d
virtio_pci: fix use after free on release

KASan detected a use-after-free error in virtio-pci remove code. In
virtio_pci_remove(), vp_dev is still used after being freed in
unregister_virtio_device() (in virtio_pci_release_dev() more
precisely).

To fix, keep a reference until cleanup is done.

Fixes: 63bd62a08ca4 ("virtio_pci: defer kfree until release callback")
Reported-by: Jerome Marchand <jmarchan@redhat.com>
Cc: stable@vger.kernel.org
Cc: Sasha Levin <sasha.levin@oracle.com>
Signed-off-by: Michael S. Tsirkin <mst@redhat.com>
Tested-by: Jerome Marchand <jmarchan@redhat.com>
drivers/virtio/virtio_pci_common.c