On Tue, Apr 17, 2012 at 11:19:42AM +0800, Jason Wang wrote:> On 04/16/2012 09:28 PM, Michael S. Tsirkin wrote:Heh, I see. How about> >On Mon, Apr 16, 2012 at 02:08:25PM +0800, Jason Wang wrote:> > The problem happens when we want to disable backend. At this time> >>When zerocopy socket is used, ubufs pointer were used in handle_tx()> >
> >>without any validation. This would cause NULL pointer deference after
> >>it has been freed in vhost_net_set_backend(). Fix this by check the
> >>pointer before using it.
> >>
> >>Signed-off-by: Jason Wang<jasowang@xxxxxxxxxx>
> >OK so it's NULL dereference and not user after free:)
> >Also could you clarify how does this happen pls?
> >Don't we always initialize ubufs when vhost_sock_zcopy is set?
> ubufs were assigned to NULL and it may be dereferenced by
> handle_tx():
- zcopy = vhost_sock_zcopy(sock);
+ zcopy = vq->ubufs;