Page MenuHomeFreeBSD

miibus: Use a bus_child_deleted method to free ivars for children
ClosedPublic

Authored by jhb on Oct 31 2024, 8:36 PM.
Tags
None
Referenced Files
Unknown Object (File)
Sun, Mar 22, 5:17 PM
Unknown Object (File)
Thu, Mar 12, 1:49 PM
Unknown Object (File)
Mon, Mar 9, 8:31 PM
Unknown Object (File)
Mon, Mar 9, 1:55 PM
Unknown Object (File)
Mon, Mar 9, 1:48 AM
Unknown Object (File)
Sat, Mar 7, 2:32 AM
Unknown Object (File)
Tue, Mar 3, 9:29 PM
Unknown Object (File)
Tue, Mar 3, 5:23 AM
Subscribers
None

Details

Summary

If a device was detached (e.g. via devctl) and then re-attached, the
ivars would be freed by the previous bus_child_detached method during
detach, but device_get_ivars during the subsequent attach would return
a stale pointer resulting in a use after free.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Not Applicable
Unit
Tests Not Applicable