[Intel-wired-lan] [PATCH iwl-net v1] ice: fix use-after-free in dynamic port cleanup
Marcin Szycik
marcin.szycik at linux.intel.com
Tue Jul 14 14:14:15 UTC 2026
On 14.07.2026 08:39, xuanqiang.luo at linux.dev wrote:
> From: Xuanqiang Luo <luoxuanqiang at kylinos.cn>
>
> ice_dealloc_dynamic_port() uses dyn_port->vsi->idx to erase the dynamic
> port from pf->dyn_ports. However, it frees the VSI before reading the
> index for the erase, resulting in a use-after-free.
>
> Follow the reverse of the allocation order in ice_alloc_dynamic_port()
> by erasing the xarray entry before freeing the VSI.
>
> Fixes: eda69d654c7e ("ice: add basic devlink subfunctions support")
> Cc: stable at vger.kernel.org
> Signed-off-by: Xuanqiang Luo <luoxuanqiang at kylinos.cn>
Reviewed-by: Marcin Szycik <marcin.szycik at linux.intel.com>
Thank you!
I wonder how such a glaring issue survived in the codebase for so long.
Perhaps ice_vsi_free() exited early for some reason.
> ---
> drivers/net/ethernet/intel/ice/devlink/port.c | 2 +-
> 1 file changed, 1 insertion(+), 1 deletion(-)
>
> diff --git a/drivers/net/ethernet/intel/ice/devlink/port.c b/drivers/net/ethernet/intel/ice/devlink/port.c
> index 2a2e56777f9f7..3ede246490027 100644
> --- a/drivers/net/ethernet/intel/ice/devlink/port.c
> +++ b/drivers/net/ethernet/intel/ice/devlink/port.c
> @@ -590,8 +590,8 @@ static void ice_dealloc_dynamic_port(struct ice_dynamic_port *dyn_port)
>
> xa_erase(&pf->sf_nums, devlink_port->attrs.pci_sf.sf);
> ice_eswitch_detach_sf(pf, dyn_port);
> - ice_vsi_free(dyn_port->vsi);
> xa_erase(&pf->dyn_ports, dyn_port->vsi->idx);
> + ice_vsi_free(dyn_port->vsi);
> kfree(dyn_port);
> }
>
More information about the Intel-wired-lan
mailing list