From nobody Sun Feb 8 18:01:25 2026 Delivered-To: importer@patchew.org Received-SPF: pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) client-ip=192.237.175.120; envelope-from=xen-devel-bounces@lists.xenproject.org; helo=lists.xenproject.org; Authentication-Results: mx.zohomail.com; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org ARC-Seal: i=1; a=rsa-sha256; t=1585044808; cv=none; d=zohomail.com; s=zohoarc; b=Glgfgx5qVsHkK22ibAe1EO9pl91H0gRIASYu0wQ7tcKXXmvgGd/ODJlD9EY+wpCMaFQLhEQadX0jyZ9PIEsVtuYk/cI9laYIKENgRDGErahN7DDNQ1NnhZgenQNXzehkC5hoHIpP2DSVU5CFrskjcvab43iv++yFD66K5vtd85w= ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=zohomail.com; s=zohoarc; t=1585044808; h=Cc:Date:From:List-Subscribe:List-Post:List-Id:List-Help:List-Unsubscribe:Message-ID:Sender:Subject:To; bh=rGyNHeXXIlzjDbX0tVqIHpbqdO6BTzJDxiVObCEeblc=; b=c+aDvxrNE20MqFZDRKr/RdDcSDZDfvVvI8x5gWEhuGh35L8LjGGmxLiZ4qEIRH4aDmHzMqaDbMcHsQzEGqTLUJnQ07HizIrJb5rpnT1DNDrZX1Jno2JcqWzYW75/ef/1D+b4IfvbQhdoRgfgz8/kH7kXU5TfoRmIdSV+NYMV8zk= ARC-Authentication-Results: i=1; mx.zohomail.com; spf=pass (zohomail.com: domain of lists.xenproject.org designates 192.237.175.120 as permitted sender) smtp.mailfrom=xen-devel-bounces@lists.xenproject.org Return-Path: Received: from lists.xenproject.org (lists.xenproject.org [192.237.175.120]) by mx.zohomail.com with SMTPS id 1585044808329395.22298594108054; Tue, 24 Mar 2020 03:13:28 -0700 (PDT) Received: from localhost ([127.0.0.1] helo=lists.xenproject.org) by lists.xenproject.org with esmtp (Exim 4.89) (envelope-from ) id 1jGgYQ-0001HY-F7; Tue, 24 Mar 2020 10:13:02 +0000 Received: from us1-rack-iad1.inumbo.com ([172.99.69.81]) by lists.xenproject.org with esmtp (Exim 4.89) (envelope-from ) id 1jGgYO-0001HR-PP for xen-devel@lists.xenproject.org; Tue, 24 Mar 2020 10:13:00 +0000 Received: from mx2.suse.de (unknown [195.135.220.15]) by us1-rack-iad1.inumbo.com (Halon) with ESMTPS id 0a024d44-6db8-11ea-92cf-bc764e2007e4; Tue, 24 Mar 2020 10:13:00 +0000 (UTC) Received: from relay2.suse.de (unknown [195.135.220.254]) by mx2.suse.de (Postfix) with ESMTP id 38649AEE6; Tue, 24 Mar 2020 10:12:59 +0000 (UTC) X-Inumbo-ID: 0a024d44-6db8-11ea-92cf-bc764e2007e4 X-Virus-Scanned: by amavisd-new at test-mx.suse.de From: Juergen Gross To: xen-devel@lists.xenproject.org Date: Tue, 24 Mar 2020 11:12:57 +0100 Message-Id: <20200324101257.20781-1-jgross@suse.com> X-Mailer: git-send-email 2.16.4 Subject: [Xen-devel] [PATCH] tools/xenstore: fix a use after free problem in xenstored X-BeenThere: xen-devel@lists.xenproject.org X-Mailman-Version: 2.1.23 Precedence: list List-Id: Xen developer discussion List-Unsubscribe: , List-Post: List-Help: List-Subscribe: , Cc: Juergen Gross , Ian Jackson , Wei Liu Errors-To: xen-devel-bounces@lists.xenproject.org Sender: "Xen-devel" Content-Transfer-Encoding: quoted-printable MIME-Version: 1.0 Content-Type: text/plain; charset="utf-8" Commit 562a1c0f7ef3fb ("tools/xenstore: dont unlink connection object twice") introduced a potential use after free problem in domain_cleanup(): after calling talloc_unlink() for domain->conn domain->conn is set to NULL. The problem is that domain is registered as talloc child of domain->conn, so it might be freed by the talloc_unlink() call. Fixes: 562a1c0f7ef3fb ("tools/xenstore: dont unlink connection object twice= ") Signed-off-by: Juergen Gross --- tools/xenstore/xenstored_domain.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/tools/xenstore/xenstored_domain.c b/tools/xenstore/xenstored_d= omain.c index baddaba5df..5858185211 100644 --- a/tools/xenstore/xenstored_domain.c +++ b/tools/xenstore/xenstored_domain.c @@ -214,6 +214,7 @@ static void domain_cleanup(void) { xc_dominfo_t dominfo; struct domain *domain; + struct connection *conn; int notify =3D 0; =20 again: @@ -230,8 +231,10 @@ static void domain_cleanup(void) continue; } if (domain->conn) { - talloc_unlink(talloc_autofree_context(), domain->conn); + /* domain is a talloc child of domain->conn. */ + conn =3D domain->conn; domain->conn =3D NULL; + talloc_unlink(talloc_autofree_context(), conn); notify =3D 0; /* destroy_domain() fires the watch */ goto again; } --=20 2.16.4