[PATCH v3 0/2] 9p: fix guest-triggered Treaddir/ACPI eject UAF

Christian Schoenebeck posted 2 patches 1 day, 17 hours ago
Patches applied successfully (tree, apply log)
git fetch https://github.com/patchew-project/qemu tags/patchew/cover.1784809978.git.qemu._5Foss@crudebyte.com
Maintainers: Christian Schoenebeck <qemu_oss@crudebyte.com>, Greg Kurz <groug@kaod.org>, "Michael S. Tsirkin" <mst@redhat.com>, Stefano Stabellini <sstabellini@kernel.org>, Anthony PERARD <anthony@xenproject.org>, "Edgar E. Iglesias" <edgar.iglesias@gmail.com>
hw/9pfs/9p.c               |  1 +
hw/9pfs/virtio-9p-device.c |  1 +
hw/9pfs/xen-9p-backend.c   | 17 +++++++++++++++--
3 files changed, 17 insertions(+), 2 deletions(-)
[PATCH v3 0/2] 9p: fix guest-triggered Treaddir/ACPI eject UAF
Posted by Christian Schoenebeck 1 day, 17 hours ago
A guest can trigger unplugging 9pfs server's virtio-pci device via ACPI
eject. As a consequence the device is unrealized, server's internal state
is freed while pending coroutines would still have access to them, causing
a potential heap-use-after-free.

Overview Patches:

 - Patch 1: this is the core fix, that drains all PDUs (i.e. coroutines
   that handle individual pending requests in parallel) before freeing
   server state.

 - Patch 2: fixes a similar identified issue with the Xen transport, even
   though not triggered via ACPI, it is also prone to UAF, plus a resource
   leak.

v3:
  - Patch 2: set s->transport = NULL in v9fs_device_unrealize_common()
    and make the idempotent check just guard the v9fs_reset(s) and
    v9fs_device_unrealize_common(s) calls in xen_9pfs_disconnect() to
    prevent a NULL pointer dereference.

v2: [ https://lore.kernel.org/qemu-devel/cover.1784392605.git.qemu_oss@crudebyte.com/ ]
  - Patch 1: Make Jia the official author of this patch.
  - Drop prev. patch 2 ("hw/9pfs/virtio: disable hotpluggable property...")
  - Patch 2: defer explict xen_9pfs_disconnect() call from error paths of
    xen_9pfs_pdu_vmarshal() and xen_9pfs_pdu_vunmarshal().

Christian Schoenebeck (1):
  hw/9pfs/xen: drain in-flight PDUs before xen-9p disconnect

Jia Jia (1):
  hw/9pfs/virtio: drain in-flight PDUs before virtio-9p unrealize

 hw/9pfs/9p.c               |  1 +
 hw/9pfs/virtio-9p-device.c |  1 +
 hw/9pfs/xen-9p-backend.c   | 17 +++++++++++++++--
 3 files changed, 17 insertions(+), 2 deletions(-)

-- 
2.47.3
Re: [PATCH v3 0/2] 9p: fix guest-triggered Treaddir/ACPI eject UAF
Posted by Christian Schoenebeck 22 hours ago
On Thursday, 23 July 2026 14:43:24 CEST Christian Schoenebeck wrote:
> A guest can trigger unplugging 9pfs server's virtio-pci device via ACPI
> eject. As a consequence the device is unrealized, server's internal state
> is freed while pending coroutines would still have access to them, causing
> a potential heap-use-after-free.
> 
> Overview Patches:
> 
>  - Patch 1: this is the core fix, that drains all PDUs (i.e. coroutines
>    that handle individual pending requests in parallel) before freeing
>    server state.
> 
>  - Patch 2: fixes a similar identified issue with the Xen transport, even
>    though not triggered via ACPI, it is also prone to UAF, plus a resource
>    leak.
> 
> v3:
>   - Patch 2: set s->transport = NULL in v9fs_device_unrealize_common()
>     and make the idempotent check just guard the v9fs_reset(s) and
>     v9fs_device_unrealize_common(s) calls in xen_9pfs_disconnect() to
>     prevent a NULL pointer dereference.
> 
> v2: [
> https://lore.kernel.org/qemu-devel/cover.1784392605.git.qemu_oss@crudebyte.
> com/ ] - Patch 1: Make Jia the official author of this patch.
>   - Drop prev. patch 2 ("hw/9pfs/virtio: disable hotpluggable property...")
>   - Patch 2: defer explict xen_9pfs_disconnect() call from error paths of
>     xen_9pfs_pdu_vmarshal() and xen_9pfs_pdu_vunmarshal().
> 
> Christian Schoenebeck (1):
>   hw/9pfs/xen: drain in-flight PDUs before xen-9p disconnect
> 
> Jia Jia (1):
>   hw/9pfs/virtio: drain in-flight PDUs before virtio-9p unrealize
> 
>  hw/9pfs/9p.c               |  1 +
>  hw/9pfs/virtio-9p-device.c |  1 +
>  hw/9pfs/xen-9p-backend.c   | 17 +++++++++++++++--
>  3 files changed, 17 insertions(+), 2 deletions(-)

Queued on 9p.next:
https://github.com/cschoenebeck/qemu/commits/9p.next

Thanks!

/Christian