On Thursday, 23 July 2026 14:43:24 CEST Christian Schoenebeck wrote:
> A guest can trigger unplugging 9pfs server's virtio-pci device via ACPI
> eject. As a consequence the device is unrealized, server's internal state
> is freed while pending coroutines would still have access to them, causing
> a potential heap-use-after-free.
>
> Overview Patches:
>
> - Patch 1: this is the core fix, that drains all PDUs (i.e. coroutines
> that handle individual pending requests in parallel) before freeing
> server state.
>
> - Patch 2: fixes a similar identified issue with the Xen transport, even
> though not triggered via ACPI, it is also prone to UAF, plus a resource
> leak.
>
> v3:
> - Patch 2: set s->transport = NULL in v9fs_device_unrealize_common()
> and make the idempotent check just guard the v9fs_reset(s) and
> v9fs_device_unrealize_common(s) calls in xen_9pfs_disconnect() to
> prevent a NULL pointer dereference.
>
> v2: [
> https://lore.kernel.org/qemu-devel/cover.1784392605.git.qemu_oss@crudebyte.
> com/ ] - Patch 1: Make Jia the official author of this patch.
> - Drop prev. patch 2 ("hw/9pfs/virtio: disable hotpluggable property...")
> - Patch 2: defer explict xen_9pfs_disconnect() call from error paths of
> xen_9pfs_pdu_vmarshal() and xen_9pfs_pdu_vunmarshal().
>
> Christian Schoenebeck (1):
> hw/9pfs/xen: drain in-flight PDUs before xen-9p disconnect
>
> Jia Jia (1):
> hw/9pfs/virtio: drain in-flight PDUs before virtio-9p unrealize
>
> hw/9pfs/9p.c | 1 +
> hw/9pfs/virtio-9p-device.c | 1 +
> hw/9pfs/xen-9p-backend.c | 17 +++++++++++++++--
> 3 files changed, 17 insertions(+), 2 deletions(-)
Queued on 9p.next:
https://github.com/cschoenebeck/qemu/commits/9p.next
Thanks!
/Christian