]> git.ipfire.org Git - thirdparty/kernel/linux.git/commitdiff
KVM: x86: Nullify irqfd->producer if updating IRTE for bypass fails
authorleixiang <leixiang@kylinos.cn>
Mon, 22 Jun 2026 07:51:01 +0000 (15:51 +0800)
committerSean Christopherson <seanjc@google.com>
Wed, 8 Jul 2026 16:43:20 +0000 (09:43 -0700)
Nullify irqfd->producer if updating the IRTE for bypass fails, as leaving a
dangling pointer will result in a use-after-free if the irqfd is reachable
through KVM's routing, but the producer is freed separately.  E.g. for VFIO
PCI, the producer is embedded in struct "vfio_pci_irq_ctx" and freed when
the vector is disabled, which can happen independent of routing updates.

Fixes: 77e1b8332d1d ("KVM: x86: Decouple device assignment from IRQ bypass")
Cc: stable@vger.kernel.org
Signed-off-by: leixiang <leixiang@kylinos.cn>
Link: https://patch.msgid.link/1782119051448443.14545.seg@mailgw.kylinos.cn
[sean: drop PPC change, massage changelog]
Signed-off-by: Sean Christopherson <seanjc@google.com>
arch/x86/kvm/irq.c

index 8c62c6d4d5c173c7f0a88748b18f690fa538f52f..cb8ac4b9b0d748eb4d161913eb9d7621c49ce825 100644 (file)
@@ -488,8 +488,10 @@ int kvm_arch_irq_bypass_add_producer(struct irq_bypass_consumer *cons,
 
        if (irqfd->irq_entry.type == KVM_IRQ_ROUTING_MSI) {
                ret = kvm_pi_update_irte(irqfd, &irqfd->irq_entry);
-               if (ret)
+               if (ret) {
                        kvm->arch.nr_possible_bypass_irqs--;
+                       irqfd->producer = NULL;
+               }
        }
        spin_unlock_irq(&kvm->irqfds.lock);