DPDK patches and discussions
 help / color / mirror / Atom feed
From: bugzilla@dpdk.org
To: dev@dpdk.org
Subject: [DPDK/ethdev Bug 1550] Use after free in E1000 driver
Date: Wed, 25 Sep 2024 16:31:16 +0000	[thread overview]
Message-ID: <bug-1550-3@http.bugs.dpdk.org/> (raw)

[-- Attachment #1: Type: text/plain, Size: 11945 bytes --]

https://bugs.dpdk.org/show_bug.cgi?id=1550

            Bug ID: 1550
           Summary: Use after free in E1000 driver
           Product: DPDK
           Version: unspecified
          Hardware: All
                OS: All
            Status: UNCONFIRMED
          Severity: major
          Priority: Normal
         Component: ethdev
          Assignee: dev@dpdk.org
          Reporter: stephen@networkplumber.org
  Target Milestone: ---

If function attributes are added to rte_malloc() Gcc will detect use after free
in e1000.

[1048/2957] Compiling C object
drivers/libtmp_rte_net_e1000.a.p/net_e1000_igb_ethdev.c.o
In file included from ../drivers/net/e1000/base/e1000_hw.h:8,
                 from ../drivers/net/e1000/base/e1000_api.h:8,
                 from ../drivers/net/e1000/igb_ethdev.c:28:
../drivers/net/e1000/igb_ethdev.c: In function ‘igb_delete_2tuple_filter’:
../drivers/net/e1000/igb_ethdev.c:3914:49: warning: pointer ‘filter’ used after
‘rte_free’ [-Wuse-after-free]
 3914 |         E1000_WRITE_REG(hw, E1000_IMIREXT(filter->index), 0);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
‘E1000_PCI_REG_WRITE’
   76 |         rte_write32((rte_cpu_to_le_32(value)), reg)
      |                                                ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
‘E1000_PCI_REG_ADDR’
  121 |         E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value))
      |                             ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3914:9: note: in expansion of macro
‘E1000_WRITE_REG’
 3914 |         E1000_WRITE_REG(hw, E1000_IMIREXT(filter->index), 0);
      |         ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3914:29: note: in expansion of macro
‘E1000_IMIREXT’
 3914 |         E1000_WRITE_REG(hw, E1000_IMIREXT(filter->index), 0);
      |                             ^~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3910:9: note: call to ‘rte_free’ here
 3910 |         rte_free(filter);
      |         ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3913:46: warning: pointer ‘filter’ used after
‘rte_free’ [-Wuse-after-free]
 3913 |         E1000_WRITE_REG(hw, E1000_IMIR(filter->index), 0);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
‘E1000_PCI_REG_WRITE’
   76 |         rte_write32((rte_cpu_to_le_32(value)), reg)
      |                                                ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
‘E1000_PCI_REG_ADDR’
  121 |         E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value))
      |                             ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3913:9: note: in expansion of macro
‘E1000_WRITE_REG’
 3913 |         E1000_WRITE_REG(hw, E1000_IMIR(filter->index), 0);
      |         ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3913:29: note: in expansion of macro
‘E1000_IMIR’
 3913 |         E1000_WRITE_REG(hw, E1000_IMIR(filter->index), 0);
      |                             ^~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3910:9: note: call to ‘rte_free’ here
 3910 |         rte_free(filter);
      |         ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3912:46: warning: pointer ‘filter’ used after
‘rte_free’ [-Wuse-after-free]
 3912 |         E1000_WRITE_REG(hw, E1000_TTQF(filter->index),
E1000_TTQF_DISABLE_MASK);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
‘E1000_PCI_REG_WRITE’
   76 |         rte_write32((rte_cpu_to_le_32(value)), reg)
      |                                                ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
‘E1000_PCI_REG_ADDR’
  121 |         E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value))
      |                             ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3912:9: note: in expansion of macro
‘E1000_WRITE_REG’
 3912 |         E1000_WRITE_REG(hw, E1000_TTQF(filter->index),
E1000_TTQF_DISABLE_MASK);
      |         ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3912:29: note: in expansion of macro
‘E1000_TTQF’
 3912 |         E1000_WRITE_REG(hw, E1000_TTQF(filter->index),
E1000_TTQF_DISABLE_MASK);
      |                             ^~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:3910:9: note: call to ‘rte_free’ here
 3910 |         rte_free(filter);
      |         ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c: In function
‘igb_delete_5tuple_filter_82576’:
../drivers/net/e1000/igb_ethdev.c:4359:49: warning: pointer ‘filter’ used after
‘rte_free’ [-Wuse-after-free]
 4359 |         E1000_WRITE_REG(hw, E1000_IMIREXT(filter->index), 0);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
‘E1000_PCI_REG_WRITE’
   76 |         rte_write32((rte_cpu_to_le_32(value)), reg)
      |                                                ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
‘E1000_PCI_REG_ADDR’
  121 |         E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value))
      |                             ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4359:9: note: in expansion of macro
‘E1000_WRITE_REG’
 4359 |         E1000_WRITE_REG(hw, E1000_IMIREXT(filter->index), 0);
      |         ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4359:29: note: in expansion of macro
‘E1000_IMIREXT’
 4359 |         E1000_WRITE_REG(hw, E1000_IMIREXT(filter->index), 0);
      |                             ^~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4351:9: note: call to ‘rte_free’ here
 4351 |         rte_free(filter);
      |         ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4358:46: warning: pointer ‘filter’ used after
‘rte_free’ [-Wuse-after-free]
 4358 |         E1000_WRITE_REG(hw, E1000_IMIR(filter->index), 0);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
‘E1000_PCI_REG_WRITE’
   76 |         rte_write32((rte_cpu_to_le_32(value)), reg)
      |                                                ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
‘E1000_PCI_REG_ADDR’
  121 |         E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value))
      |                             ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4358:9: note: in expansion of macro
‘E1000_WRITE_REG’
 4358 |         E1000_WRITE_REG(hw, E1000_IMIR(filter->index), 0);
      |         ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4358:29: note: in expansion of macro
‘E1000_IMIR’
 4358 |         E1000_WRITE_REG(hw, E1000_IMIR(filter->index), 0);
      |                             ^~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4351:9: note: call to ‘rte_free’ here
 4351 |         rte_free(filter);
      |         ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4357:46: warning: pointer ‘filter’ used after
‘rte_free’ [-Wuse-after-free]
 4357 |         E1000_WRITE_REG(hw, E1000_SPQF(filter->index), 0);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
‘E1000_PCI_REG_WRITE’
   76 |         rte_write32((rte_cpu_to_le_32(value)), reg)
      |                                                ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
‘E1000_PCI_REG_ADDR’
  121 |         E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value))
      |                             ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4357:9: note: in expansion of macro
‘E1000_WRITE_REG’
 4357 |         E1000_WRITE_REG(hw, E1000_SPQF(filter->index), 0);
      |         ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4357:29: note: in expansion of macro
‘E1000_SPQF’
 4357 |         E1000_WRITE_REG(hw, E1000_SPQF(filter->index), 0);
      |                             ^~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4351:9: note: call to ‘rte_free’ here
 4351 |         rte_free(filter);
      |         ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4356:46: warning: pointer ‘filter’ used after
‘rte_free’ [-Wuse-after-free]
 4356 |         E1000_WRITE_REG(hw, E1000_SAQF(filter->index), 0);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
‘E1000_PCI_REG_WRITE’
   76 |         rte_write32((rte_cpu_to_le_32(value)), reg)
      |                                                ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
‘E1000_PCI_REG_ADDR’
  121 |         E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value))
      |                             ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4356:9: note: in expansion of macro
‘E1000_WRITE_REG’
 4356 |         E1000_WRITE_REG(hw, E1000_SAQF(filter->index), 0);
      |         ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4356:29: note: in expansion of macro
‘E1000_SAQF’
 4356 |         E1000_WRITE_REG(hw, E1000_SAQF(filter->index), 0);
      |                             ^~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4351:9: note: call to ‘rte_free’ here
 4351 |         rte_free(filter);
      |         ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4355:46: warning: pointer ‘filter’ used after
‘rte_free’ [-Wuse-after-free]
 4355 |         E1000_WRITE_REG(hw, E1000_DAQF(filter->index), 0);
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
‘E1000_PCI_REG_WRITE’
   76 |         rte_write32((rte_cpu_to_le_32(value)), reg)
      |                                                ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
‘E1000_PCI_REG_ADDR’
  121 |         E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value))
      |                             ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4355:9: note: in expansion of macro
‘E1000_WRITE_REG’
 4355 |         E1000_WRITE_REG(hw, E1000_DAQF(filter->index), 0);
      |         ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4355:29: note: in expansion of macro
‘E1000_DAQF’
 4355 |         E1000_WRITE_REG(hw, E1000_DAQF(filter->index), 0);
      |                             ^~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4351:9: note: call to ‘rte_free’ here
 4351 |         rte_free(filter);
      |         ^~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4353:46: warning: pointer ‘filter’ used after
‘rte_free’ [-Wuse-after-free]
 4353 |         E1000_WRITE_REG(hw, E1000_FTQF(filter->index),
../drivers/net/e1000/base/e1000_osdep.h:76:48: note: in definition of macro
‘E1000_PCI_REG_WRITE’
   76 |         rte_write32((rte_cpu_to_le_32(value)), reg)
      |                                                ^~~
../drivers/net/e1000/base/e1000_osdep.h:121:29: note: in expansion of macro
‘E1000_PCI_REG_ADDR’
  121 |         E1000_PCI_REG_WRITE(E1000_PCI_REG_ADDR((hw), (reg)), (value))
      |                             ^~~~~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4353:9: note: in expansion of macro
‘E1000_WRITE_REG’
 4353 |         E1000_WRITE_REG(hw, E1000_FTQF(filter->index),
      |         ^~~~~~~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4353:29: note: in expansion of macro
‘E1000_FTQF’
 4353 |         E1000_WRITE_REG(hw, E1000_FTQF(filter->index),
      |                             ^~~~~~~~~~
../drivers/net/e1000/igb_ethdev.c:4351:9: note: call to ‘rte_free’ here
 4351 |         rte_free(filter);
      |         ^~~~~~~~~~~~~~~~

-- 
You are receiving this mail because:
You are the assignee for the bug.

[-- Attachment #2: Type: text/html, Size: 13884 bytes --]

                 reply	other threads:[~2024-09-25 16:31 UTC|newest]

Thread overview: [no followups] expand[flat|nested]  mbox.gz  Atom feed

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

  Avoid top-posting and favor interleaved quoting:
  https://en.wikipedia.org/wiki/Posting_style#Interleaved_style

* Reply using the --to, --cc, and --in-reply-to
  switches of git-send-email(1):

  git send-email \
    --in-reply-to=bug-1550-3@http.bugs.dpdk.org/ \
    --to=bugzilla@dpdk.org \
    --cc=dev@dpdk.org \
    /path/to/YOUR_REPLY

  https://kernel.org/pub/software/scm/git/docs/git-send-email.html

* If your mail client supports setting the In-Reply-To header
  via mailto: links, try the mailto: link
Be sure your reply has a Subject: header at the top and a blank line before the message body.
This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for NNTP newsgroup(s).