[PATCH] hw/usb: Fix USB MTP Use-After-Free in usb_mtp_deletefn List Iteration

Tommaso Califano posted 1 patch 1 week, 3 days ago
hw/usb/dev-mtp.c | 4 ++--
1 file changed, 2 insertions(+), 2 deletions(-)
[PATCH] hw/usb: Fix USB MTP Use-After-Free in usb_mtp_deletefn List Iteration
Posted by Tommaso Califano 1 week, 3 days ago
In QEMU's USB MTP (Media Transfer Protocol) device emulation, the usb_mtp_deletefn()
function in hw/usb/dev-mtp.c iterates over a child object list using QLIST_FOREACH
while the recursive call may free the current element. After the free, the macro reads
the le_next field from freed memory to advance the iterator.

Replace QLIST_FOREACH with QLIST_FOREACH_SAFE, which saves the next pointer before the
iteration body executes.

Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3991
Signed-off-by: Tommaso Califano <tcalifan@redhat.com>
---
 hw/usb/dev-mtp.c | 4 ++--
 1 file changed, 2 insertions(+), 2 deletions(-)

diff --git a/hw/usb/dev-mtp.c b/hw/usb/dev-mtp.c
index 1d8cfd32dc..c2d36a73cf 100644
--- a/hw/usb/dev-mtp.c
+++ b/hw/usb/dev-mtp.c
@@ -1152,7 +1152,7 @@ enum {
 
 static int usb_mtp_deletefn(MTPState *s, MTPObject *o, uint32_t trans)
 {
-    MTPObject *iter, *iter2;
+    MTPObject *iter, *iter2, *iter2_next;
     int ret = 0;
 
     /*
@@ -1161,7 +1161,7 @@ static int usb_mtp_deletefn(MTPState *s, MTPObject *o, uint32_t trans)
 
     QLIST_FOREACH(iter, &o->children, list) {
         if (iter->format == FMT_ASSOCIATION) {
-            QLIST_FOREACH(iter2, &iter->children, list) {
+            QLIST_FOREACH_SAFE(iter2, &iter->children, list, iter2_next) {
                 ret |= usb_mtp_deletefn(s, iter2, trans);
             }
         }
-- 
2.55.0
Re: [PATCH] hw/usb: Fix USB MTP Use-After-Free in usb_mtp_deletefn List Iteration
Posted by Daniel P. Berrangé 3 days, 3 hours ago
On Wed, Sep 16, 2026 at 06:18:26PM +0200, Tommaso Califano wrote:
> In QEMU's USB MTP (Media Transfer Protocol) device emulation, the usb_mtp_deletefn()
> function in hw/usb/dev-mtp.c iterates over a child object list using QLIST_FOREACH
> while the recursive call may free the current element. After the free, the macro reads
> the le_next field from freed memory to advance the iterator.
> 
> Replace QLIST_FOREACH with QLIST_FOREACH_SAFE, which saves the next pointer before the
> iteration body executes.
> 
> Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3991
> Signed-off-by: Tommaso Califano <tcalifan@redhat.com>
> ---
>  hw/usb/dev-mtp.c | 4 ++--
>  1 file changed, 2 insertions(+), 2 deletions(-)

Reviewed-by: Daniel P. Berrangé <berrange@redhat.com>


With regards,
Daniel
-- 
|: https://berrange.com       ~~        https://hachyderm.io/@berrange :|
|: https://libvirt.org          ~~          https://entangle-photo.org :|
|: https://pixelfed.art/berrange   ~~    https://fstop138.berrange.com :|