From mboxrd@z Thu Jan 1 00:00:00 1970
Return-Path:
Received: from mails.dpdk.org (mails.dpdk.org [217.70.189.124])
by inbox.dpdk.org (Postfix) with ESMTP id 5D85245A2C;
Wed, 25 Sep 2024 18:31:18 +0200 (CEST)
Received: from mails.dpdk.org (localhost [127.0.0.1])
by mails.dpdk.org (Postfix) with ESMTP id 176634025D;
Wed, 25 Sep 2024 18:31:18 +0200 (CEST)
Received: from inbox.dpdk.org (inbox.dpdk.org [95.142.172.178])
by mails.dpdk.org (Postfix) with ESMTP id 4BC46400EF
for ; Wed, 25 Sep 2024 18:31:16 +0200 (CEST)
Received: by inbox.dpdk.org (Postfix, from userid 33)
id 3B64345A2D; Wed, 25 Sep 2024 18:31:16 +0200 (CEST)
From: bugzilla@dpdk.org
To: dev@dpdk.org
Subject: [DPDK/ethdev Bug 1550] Use after free in E1000 driver
Date: Wed, 25 Sep 2024 16:31:16 +0000
X-Bugzilla-Reason: AssignedTo
X-Bugzilla-Type: new
X-Bugzilla-Watch-Reason: None
X-Bugzilla-Product: DPDK
X-Bugzilla-Component: ethdev
X-Bugzilla-Version: unspecified
X-Bugzilla-Keywords:
X-Bugzilla-Severity: major
X-Bugzilla-Who: stephen@networkplumber.org
X-Bugzilla-Status: UNCONFIRMED
X-Bugzilla-Resolution:
X-Bugzilla-Priority: Normal
X-Bugzilla-Assigned-To: dev@dpdk.org
X-Bugzilla-Target-Milestone: ---
X-Bugzilla-Flags:
X-Bugzilla-Changed-Fields: bug_id short_desc product version rep_platform
op_sys bug_status bug_severity priority component assigned_to reporter
target_milestone
Message-ID:
Content-Type: multipart/alternative; boundary=17272818760.5cc80DcD.3554884
Content-Transfer-Encoding: 7bit
X-Bugzilla-URL: http://bugs.dpdk.org/
Auto-Submitted: auto-generated
X-Auto-Response-Suppress: All
MIME-Version: 1.0
X-BeenThere: dev@dpdk.org
X-Mailman-Version: 2.1.29
Precedence: list
List-Id: DPDK patches and discussions
List-Unsubscribe: ,
List-Archive:
List-Post:
List-Help:
List-Subscribe: ,
Errors-To: dev-bounces@dpdk.org
--17272818760.5cc80DcD.3554884
Date: Wed, 25 Sep 2024 18:31:16 +0200
MIME-Version: 1.0
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
X-Bugzilla-URL: http://bugs.dpdk.org/
Auto-Submitted: auto-generated
X-Auto-Response-Suppress: All
https://bugs.dpdk.org/show_bug.cgi?id=3D1550
Bug ID: 1550
Summary: Use after free in E1000 driver
Product: DPDK
Version: unspecified
Hardware: All
OS: All
Status: UNCONFIRMED
Severity: major
Priority: Normal
Component: ethdev
Assignee: dev@dpdk.org
Reporter: stephen@networkplumber.org
Target Milestone: ---
If function attributes are added to rte_malloc() Gcc will detect use after =
free
in e1000.
[1048/2957] Compiling C object
drivers/libtmp_rte_net_e1000.a.p/net_e1000_igb_ethdev.c.o
In file included from ../drivers/net/e1000/base/e1000_hw.h:8,
from ../drivers/net/e1000/base/e1000_api.h:8,
from ../drivers/net/e1000/igb_ethdev.c:28:
../drivers/net/e1000/igb_ethdev.c: In function =E2=80=98igb_delete_2tuple_f=
ilter=E2=80=99:
../drivers/net/e1000/igb_ethdev.c:3914:49: warning: pointer =E2=80=98filter=
=E2=80=99 used after
=E2=80=98rte_free=E2=80=99 [-Wuse-after-free]
3914 | E1000_WRITE_REG(hw, E1000_IMIREXT(filter->index), 0);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
=E2=80=98E1000_PCI_REG_WRITE=E2=80=99
76 | rte_write32((rte_cpu_to_le_32(value)), reg)
| ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
=E2=80=98E1000_PCI_REG_ADDR=E2=80=99
121 | E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value=
))
| ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3914:9: note: in expansion of macro
=E2=80=98E1000_WRITE_REG=E2=80=99
3914 | E1000_WRITE_REG(hw, E1000_IMIREXT(filter->index), 0);
| ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3914:29: note: in expansion of macro
=E2=80=98E1000_IMIREXT=E2=80=99
3914 | E1000_WRITE_REG(hw, E1000_IMIREXT(filter->index), 0);
| ^~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3910:9: note: call to =E2=80=98rte_free=
=E2=80=99 here
3910 | rte_free(filter);
| ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3913:46: warning: pointer =E2=80=98filter=
=E2=80=99 used after
=E2=80=98rte_free=E2=80=99 [-Wuse-after-free]
3913 | E1000_WRITE_REG(hw, E1000_IMIR(filter->index), 0);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
=E2=80=98E1000_PCI_REG_WRITE=E2=80=99
76 | rte_write32((rte_cpu_to_le_32(value)), reg)
| ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
=E2=80=98E1000_PCI_REG_ADDR=E2=80=99
121 | E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value=
))
| ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3913:9: note: in expansion of macro
=E2=80=98E1000_WRITE_REG=E2=80=99
3913 | E1000_WRITE_REG(hw, E1000_IMIR(filter->index), 0);
| ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3913:29: note: in expansion of macro
=E2=80=98E1000_IMIR=E2=80=99
3913 | E1000_WRITE_REG(hw, E1000_IMIR(filter->index), 0);
| ^~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3910:9: note: call to =E2=80=98rte_free=
=E2=80=99 here
3910 | rte_free(filter);
| ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3912:46: warning: pointer =E2=80=98filter=
=E2=80=99 used after
=E2=80=98rte_free=E2=80=99 [-Wuse-after-free]
3912 | E1000_WRITE_REG(hw, E1000_TTQF(filter->index),
E1000_TTQF_DISABLE_MASK);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
=E2=80=98E1000_PCI_REG_WRITE=E2=80=99
76 | rte_write32((rte_cpu_to_le_32(value)), reg)
| ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
=E2=80=98E1000_PCI_REG_ADDR=E2=80=99
121 | E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value=
))
| ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3912:9: note: in expansion of macro
=E2=80=98E1000_WRITE_REG=E2=80=99
3912 | E1000_WRITE_REG(hw, E1000_TTQF(filter->index),
E1000_TTQF_DISABLE_MASK);
| ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3912:29: note: in expansion of macro
=E2=80=98E1000_TTQF=E2=80=99
3912 | E1000_WRITE_REG(hw, E1000_TTQF(filter->index),
E1000_TTQF_DISABLE_MASK);
| ^~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3910:9: note: call to =E2=80=98rte_free=
=E2=80=99 here
3910 | rte_free(filter);
| ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c: In function
=E2=80=98igb_delete_5tuple_filter_82576=E2=80=99:
../drivers/net/e1000/igb_ethdev.c:4359:49: warning: pointer =E2=80=98filter=
=E2=80=99 used after
=E2=80=98rte_free=E2=80=99 [-Wuse-after-free]
4359 | E1000_WRITE_REG(hw, E1000_IMIREXT(filter->index), 0);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
=E2=80=98E1000_PCI_REG_WRITE=E2=80=99
76 | rte_write32((rte_cpu_to_le_32(value)), reg)
| ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
=E2=80=98E1000_PCI_REG_ADDR=E2=80=99
121 | E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value=
))
| ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4359:9: note: in expansion of macro
=E2=80=98E1000_WRITE_REG=E2=80=99
4359 | E1000_WRITE_REG(hw, E1000_IMIREXT(filter->index), 0);
| ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4359:29: note: in expansion of macro
=E2=80=98E1000_IMIREXT=E2=80=99
4359 | E1000_WRITE_REG(hw, E1000_IMIREXT(filter->index), 0);
| ^~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4351:9: note: call to =E2=80=98rte_free=
=E2=80=99 here
4351 | rte_free(filter);
| ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4358:46: warning: pointer =E2=80=98filter=
=E2=80=99 used after
=E2=80=98rte_free=E2=80=99 [-Wuse-after-free]
4358 | E1000_WRITE_REG(hw, E1000_IMIR(filter->index), 0);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
=E2=80=98E1000_PCI_REG_WRITE=E2=80=99
76 | rte_write32((rte_cpu_to_le_32(value)), reg)
| ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
=E2=80=98E1000_PCI_REG_ADDR=E2=80=99
121 | E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value=
))
| ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4358:9: note: in expansion of macro
=E2=80=98E1000_WRITE_REG=E2=80=99
4358 | E1000_WRITE_REG(hw, E1000_IMIR(filter->index), 0);
| ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4358:29: note: in expansion of macro
=E2=80=98E1000_IMIR=E2=80=99
4358 | E1000_WRITE_REG(hw, E1000_IMIR(filter->index), 0);
| ^~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4351:9: note: call to =E2=80=98rte_free=
=E2=80=99 here
4351 | rte_free(filter);
| ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4357:46: warning: pointer =E2=80=98filter=
=E2=80=99 used after
=E2=80=98rte_free=E2=80=99 [-Wuse-after-free]
4357 | E1000_WRITE_REG(hw, E1000_SPQF(filter->index), 0);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
=E2=80=98E1000_PCI_REG_WRITE=E2=80=99
76 | rte_write32((rte_cpu_to_le_32(value)), reg)
| ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
=E2=80=98E1000_PCI_REG_ADDR=E2=80=99
121 | E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value=
))
| ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4357:9: note: in expansion of macro
=E2=80=98E1000_WRITE_REG=E2=80=99
4357 | E1000_WRITE_REG(hw, E1000_SPQF(filter->index), 0);
| ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4357:29: note: in expansion of macro
=E2=80=98E1000_SPQF=E2=80=99
4357 | E1000_WRITE_REG(hw, E1000_SPQF(filter->index), 0);
| ^~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4351:9: note: call to =E2=80=98rte_free=
=E2=80=99 here
4351 | rte_free(filter);
| ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4356:46: warning: pointer =E2=80=98filter=
=E2=80=99 used after
=E2=80=98rte_free=E2=80=99 [-Wuse-after-free]
4356 | E1000_WRITE_REG(hw, E1000_SAQF(filter->index), 0);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
=E2=80=98E1000_PCI_REG_WRITE=E2=80=99
76 | rte_write32((rte_cpu_to_le_32(value)), reg)
| ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
=E2=80=98E1000_PCI_REG_ADDR=E2=80=99
121 | E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value=
))
| ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4356:9: note: in expansion of macro
=E2=80=98E1000_WRITE_REG=E2=80=99
4356 | E1000_WRITE_REG(hw, E1000_SAQF(filter->index), 0);
| ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4356:29: note: in expansion of macro
=E2=80=98E1000_SAQF=E2=80=99
4356 | E1000_WRITE_REG(hw, E1000_SAQF(filter->index), 0);
| ^~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4351:9: note: call to =E2=80=98rte_free=
=E2=80=99 here
4351 | rte_free(filter);
| ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4355:46: warning: pointer =E2=80=98filter=
=E2=80=99 used after
=E2=80=98rte_free=E2=80=99 [-Wuse-after-free]
4355 | E1000_WRITE_REG(hw, E1000_DAQF(filter->index), 0);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
=E2=80=98E1000_PCI_REG_WRITE=E2=80=99
76 | rte_write32((rte_cpu_to_le_32(value)), reg)
| ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
=E2=80=98E1000_PCI_REG_ADDR=E2=80=99
121 | E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value=
))
| ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4355:9: note: in expansion of macro
=E2=80=98E1000_WRITE_REG=E2=80=99
4355 | E1000_WRITE_REG(hw, E1000_DAQF(filter->index), 0);
| ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4355:29: note: in expansion of macro
=E2=80=98E1000_DAQF=E2=80=99
4355 | E1000_WRITE_REG(hw, E1000_DAQF(filter->index), 0);
| ^~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4351:9: note: call to =E2=80=98rte_free=
=E2=80=99 here
4351 | rte_free(filter);
| ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4353:46: warning: pointer =E2=80=98filter=
=E2=80=99 used after
=E2=80=98rte_free=E2=80=99 [-Wuse-after-free]
4353 | E1000_WRITE_REG(hw, E1000_FTQF(filter->index),
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
=E2=80=98E1000_PCI_REG_WRITE=E2=80=99
76 | rte_write32((rte_cpu_to_le_32(value)), reg)
| ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
=E2=80=98E1000_PCI_REG_ADDR=E2=80=99
121 | E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value=
))
| ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4353:9: note: in expansion of macro
=E2=80=98E1000_WRITE_REG=E2=80=99
4353 | E1000_WRITE_REG(hw, E1000_FTQF(filter->index),
| ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4353:29: note: in expansion of macro
=E2=80=98E1000_FTQF=E2=80=99
4353 | E1000_WRITE_REG(hw, E1000_FTQF(filter->index),
| ^~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4351:9: note: call to =E2=80=98rte_free=
=E2=80=99 here
4351 | rte_free(filter);
| ^~~~~~~~~~~~~~~~
--=20
You are receiving this mail because:
You are the assignee for the bug.=
--17272818760.5cc80DcD.3554884
Date: Wed, 25 Sep 2024 18:31:16 +0200
MIME-Version: 1.0
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable
X-Bugzilla-URL: http://bugs.dpdk.org/
Auto-Submitted: auto-generated
X-Auto-Response-Suppress: All
Bug ID |
1550
|
Summary |
Use after free in E1000 driver
|
Product |
DPDK
|
Version |
unspecified
|
Hardware |
All
|
OS |
All
|
Status |
UNCONFIRMED
|
Severity |
major
|
Priority |
Normal
|
Component |
ethdev
|
Assignee |
dev@dpdk.org
|
Reporter |
stephen@networkplumber.org
|
Target Milestone |
---
|
You are receiving this mail because:
- You are the assignee for the bug.
=20=20=20=20=20=20=20=20=20=20
=
--17272818760.5cc80DcD.3554884--