Thread (1 message) 1 message, 1 author, 2017-04-10

Re: [PATCH v2] powerpc/eeh: Avoid use after free in eeh_handle_special_event()

From: Andrew Donnellan <hidden>
Date: 2017-04-10 07:47:29

On 10/04/17 17:11, Russell Currey wrote:
eeh_handle_special_event() is called when an EEH event is detected but
can't be narrowed down to a specific PE.  This function looks through
every PE to find one in an erroneous state, then calls the regular event
handler eeh_handle_normal_event() once it knows which PE has an error.

However, if eeh_handle_normal_event() found that the PE cannot possibly
be recovered, it will free it, rendering the passed PE stale.
This leads to a use after free in eeh_handle_special_event() as it attempts to
clear the "recovering" state on the PE after eeh_handle_normal_event() returns.

Thus, make sure the PE is valid when attempting to clear state in
eeh_handle_special_event().

Cc: <redacted> #3.10+
Reported-by: Alexey Kardashevskiy <redacted>
Signed-off-by: Russell Currey <redacted>
Reviewed-by: Andrew Donnellan <redacted>


-- 
Andrew Donnellan              OzLabs, ADL Canberra
andrew.donnellan@au1.ibm.com  IBM Australia Limited
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help