Thread (1 message) 1 message, 1 author, 2012-04-20

Re: use-after-free in usbnet

From: Huajun Li <hidden>
Date: 2012-04-20 15:07:40

On Fri, Apr 20, 2012 at 10:56 PM, Huajun Li [off-list ref] wrote:
On Fri, Apr 20, 2012 at 10:22 PM, Ming Lei [off-list ref] wrote:
quoted
On Fri, Apr 20, 2012 at 9:37 PM, Huajun Li [off-list ref] wrote:
quoted
Above patch has already been integrated to mainline. However, maybe
there still exists another potentail use-after-free issue, here is a
case:
     After release the lock in unlink_urbs(), defer_bh() may move
current skb from rxq/txq to dev->done queue, even cause the skb be
released. Then in next loop cycle, it can't refer to expected skb, and
may Oops again.
Could you explain in a bit detail? Why can't the expected skb be refered
to in next loop?

     unlink_urbs()                                           complete handler
--------------------------------------
-------------------------------------------------
    spin_unlock_irqrestore()
                                                                 rx_complete()
                                                                 derver_bh()

 __skb_unlink()

 __skb_queue_tail(&dev->done, skb)   =======> skb is moved to
dev->done, and can be freed by usbnet_bh()
     skb_queue_walk_safe()
                     tmp = skb->next   ===> refer to freed skb
Sorry, email client messed up these lines, resend it:

  unlink_urbs()                    complete handler
------------------------               ------------------------------
spin_unlock_irqrestore()
                                       rx_complete()
                                       derver_bh()
                                          __skb_unlink()
                                          __skb_queue_tail(&dev->done, skb)
                                          =======> skb is moved to dev->done,
                                        and can be freed by usbnet_bh()

skb_queue_walk_safe()
        tmp = skb->next   ===> refer to freed skb
--
To unsubscribe from this list: send the line "unsubscribe linux-usb" in
the body of a message to majordomo-u79uwXL29TY76Z2rM5mHXA@public.gmane.org
More majordomo info at  http://vger.kernel.org/majordomo-info.html
Keyboard shortcuts
hback out one level
jnext message in thread
kprevious message in thread
ldrill in
Escclose help / fold thread tree
?toggle this help