Skip to content
  • Vladimir Sementsov-Ogievskiy's avatar
    0267101a
    block/nbd: fix possible use after free of s->connect_thread · 0267101a
    Vladimir Sementsov-Ogievskiy authored
    
    
    If on nbd_close() we detach the thread (in
    nbd_co_establish_connection_cancel() thr->state becomes
    CONNECT_THREAD_RUNNING_DETACHED), after that point we should not use
    s->connect_thread (which is set to NULL), as running thread may free it
    at any time.
    
    Still nbd_co_establish_connection() does exactly this: it saves
    s->connect_thread to local variable (just for better code style) and
    use it even after yield point, when thread may be already detached.
    
    Fix that. Also check thr to be non-NULL on
    nbd_co_establish_connection() start for safety.
    
    After this patch "case CONNECT_THREAD_RUNNING_DETACHED" becomes
    impossible in the second switch in nbd_co_establish_connection().
    Still, don't add extra abort() just before the release. If it somehow
    possible to reach this "case:" it won't hurt. Anyway, good refactoring
    of all this reconnect mess will come soon.
    
    Signed-off-by: default avatarVladimir Sementsov-Ogievskiy <vsementsov@virtuozzo.com>
    Message-Id: <20210406155114.1057355-1-vsementsov@virtuozzo.com>
    Reviewed-by: default avatarRoman Kagan <rvkagan@yandex-team.ru>
    Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
    0267101a
    block/nbd: fix possible use after free of s->connect_thread
    Vladimir Sementsov-Ogievskiy authored
    
    
    If on nbd_close() we detach the thread (in
    nbd_co_establish_connection_cancel() thr->state becomes
    CONNECT_THREAD_RUNNING_DETACHED), after that point we should not use
    s->connect_thread (which is set to NULL), as running thread may free it
    at any time.
    
    Still nbd_co_establish_connection() does exactly this: it saves
    s->connect_thread to local variable (just for better code style) and
    use it even after yield point, when thread may be already detached.
    
    Fix that. Also check thr to be non-NULL on
    nbd_co_establish_connection() start for safety.
    
    After this patch "case CONNECT_THREAD_RUNNING_DETACHED" becomes
    impossible in the second switch in nbd_co_establish_connection().
    Still, don't add extra abort() just before the release. If it somehow
    possible to reach this "case:" it won't hurt. Anyway, good refactoring
    of all this reconnect mess will come soon.
    
    Signed-off-by: default avatarVladimir Sementsov-Ogievskiy <vsementsov@virtuozzo.com>
    Message-Id: <20210406155114.1057355-1-vsementsov@virtuozzo.com>
    Reviewed-by: default avatarRoman Kagan <rvkagan@yandex-team.ru>
    Signed-off-by: default avatarMax Reitz <mreitz@redhat.com>
Loading