在 2026/7/14 22:14, Marcin Szycik 写道:
On 14.07.2026 08:39,[email protected] wrote:
From: Xuanqiang Luo<[email protected]>

ice_dealloc_dynamic_port() uses dyn_port->vsi->idx to erase the dynamic
port from pf->dyn_ports. However, it frees the VSI before reading the
index for the erase, resulting in a use-after-free.

Follow the reverse of the allocation order in ice_alloc_dynamic_port()
by erasing the xarray entry before freeing the VSI.

Fixes: eda69d654c7e ("ice: add basic devlink subfunctions support")
Cc:[email protected]
Signed-off-by: Xuanqiang Luo<[email protected]>
Reviewed-by: Marcin Szycik<[email protected]>

Thank you!
I wonder how such a glaring issue survived in the codebase for so long.
Perhaps ice_vsi_free() exited early for some reason.

Thanks for the review!

Hard to say—maybe the window is quite small and the freed slab still
holds the old idx most of the time, so nothing obvious shows up.

---
  drivers/net/ethernet/intel/ice/devlink/port.c | 2 +-
  1 file changed, 1 insertion(+), 1 deletion(-)

diff --git a/drivers/net/ethernet/intel/ice/devlink/port.c 
b/drivers/net/ethernet/intel/ice/devlink/port.c
index 2a2e56777f9f7..3ede246490027 100644
--- a/drivers/net/ethernet/intel/ice/devlink/port.c
+++ b/drivers/net/ethernet/intel/ice/devlink/port.c
@@ -590,8 +590,8 @@ static void ice_dealloc_dynamic_port(struct 
ice_dynamic_port *dyn_port)
xa_erase(&pf->sf_nums, devlink_port->attrs.pci_sf.sf);
        ice_eswitch_detach_sf(pf, dyn_port);
-       ice_vsi_free(dyn_port->vsi);
        xa_erase(&pf->dyn_ports, dyn_port->vsi->idx);
+       ice_vsi_free(dyn_port->vsi);
        kfree(dyn_port);
  }

Reply via email to