[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20161024152325.GD2247@potion>
Date: Mon, 24 Oct 2016 17:23:26 +0200
From: Radim Krčmář <rkrcmar@...hat.com>
To: Ido Yariv <ido@...ery.com>
Cc: Paolo Bonzini <pbonzini@...hat.com>,
Thomas Gleixner <tglx@...utronix.de>,
Ingo Molnar <mingo@...hat.com>,
"H. Peter Anvin" <hpa@...or.com>, x86@...nel.org,
kvm@...r.kernel.org, linux-kernel@...r.kernel.org,
stable@...r.kernel.org
Subject: Re: [PATCH] KVM: x86: fix wbinvd_dirty_mask use-after-free
2016-10-21 12:39-0400, Ido Yariv:
> vcpu->arch.wbinvd_dirty_mask may still be used after freeing it,
> corrupting memory. For example, the following call trace may set a bit
> in an already freed cpu mask:
> kvm_arch_vcpu_load
> vcpu_load
> vmx_free_vcpu_nested
> vmx_free_vcpu
> kvm_arch_vcpu_free
>
> Fix this by deferring freeing of wbinvd_dirty_mask.
>
> Cc: stable@...r.kernel.org
> Signed-off-by: Ido Yariv <ido@...ery.com>
> ---
Applied, thanks.
Powered by blists - more mailing lists