46 lines
1.5 KiB
Diff
46 lines
1.5 KiB
Diff
|
|
From 81b4091eee81fe3871d836b1a684e27828cdc2be Mon Sep 17 00:00:00 2001
|
||
|
|
From: WangJian <wangjian161@huawei.com>
|
||
|
|
Date: Wed, 9 Feb 2022 10:42:33 +0800
|
||
|
|
Subject: [PATCH] nbd/server.c: fix invalid read after client was already free
|
||
|
|
|
||
|
|
In the process of NBD equipment pressurization, executing QEMU NBD will
|
||
|
|
lead to the failure of IO distribution and go to NBD_ Out process of trip().
|
||
|
|
If two or more IO go to the out process, client NBD will release in nbd_request_put().
|
||
|
|
The user after free problem that is read again in close().
|
||
|
|
Through the NBD_ Save the value of client > closing before the out process in trip
|
||
|
|
to solve the use after free problem.
|
||
|
|
|
||
|
|
Signed-off-by: wangjian161 <wangjian161@huawei.com>
|
||
|
|
---
|
||
|
|
nbd/server.c | 6 +++++-
|
||
|
|
1 file changed, 5 insertions(+), 1 deletion(-)
|
||
|
|
|
||
|
|
diff --git a/nbd/server.c b/nbd/server.c
|
||
|
|
index 895cf0a752..e8baed9705 100644
|
||
|
|
--- a/nbd/server.c
|
||
|
|
+++ b/nbd/server.c
|
||
|
|
@@ -2939,6 +2939,7 @@ static coroutine_fn void nbd_trip(void *opaque)
|
||
|
|
NBDRequestData *req;
|
||
|
|
NBDRequest request = { 0 }; /* GCC thinks it can be used uninitialized */
|
||
|
|
int ret;
|
||
|
|
+ bool client_closing;
|
||
|
|
Error *local_err = NULL;
|
||
|
|
|
||
|
|
trace_nbd_trip();
|
||
|
|
@@ -3023,8 +3024,11 @@ disconnect:
|
||
|
|
if (local_err) {
|
||
|
|
error_reportf_err(local_err, "Disconnect client, due to: ");
|
||
|
|
}
|
||
|
|
+ client_closing = client->closing;
|
||
|
|
nbd_request_put(req);
|
||
|
|
- client_close(client, true);
|
||
|
|
+ if (!client_closing) {
|
||
|
|
+ client_close(client, true);
|
||
|
|
+ }
|
||
|
|
nbd_client_put(client);
|
||
|
|
}
|
||
|
|
|
||
|
|
--
|
||
|
|
2.27.0
|
||
|
|
|