Hi Christian,

 Sure, thanks for handling this.

 Please make me the author of patch 1/3, and feel free to add:

 Signed-off-by: Jia Jia <[email protected]>

 on my behalf.

 Thanks,
 Jia

Christian Schoenebeck <[email protected]> 于2026年7月9日周四 22:20写道:

> On Thursday, 9 July 2026 15:50:36 CEST Christian Schoenebeck wrote:
> > A guest can trigger a heap-use-after-free in the virtio transport
> > unrealize path by submitting a Treaddir request and immediately
> > ejecting the device via ACPI PCI hotplug. The unrealize path frees
> > struct LocalData while a worker thread still holds a reference
> > on it, causing a UAF in local_open_nofollow().
> >
> > Fix this by draining all in-flight 9p PDUs by calling v9fs_reset()
> > before final server cleanup. This ensures all coroutines completed,
> > all FIDs are closed, and no worker thread still holds references
> > on 9p server state when it is freed.
> >
> > Reported-by: Jia Jia <[email protected]>
> > Suggested-by: Jia Jia <[email protected]>
> > Fixes: 6cecf09373 ("virtio-9p-device: add minimal unrealize handler")
> > Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/3937
> > Signed-off-by: Christian Schoenebeck <[email protected]>
> > ---
>
> Jia, if desired, I can make you the official author of this patch. If
> that's
> what you want, then please reply-to-all to this message with the same
> email
> address that you used for your report already, and acknowledge that you
> would
> be fine that I add a:
>
> Signed-off-by: Jia Jia <[email protected]>
>
> tag on behalf of you, for the reason described here:
>
> https://www.qemu.org/docs/master/devel/submitting-a-patch.html
>
> >  hw/9pfs/virtio-9p-device.c | 1 +
> >  1 file changed, 1 insertion(+)
> >
> > diff --git a/hw/9pfs/virtio-9p-device.c b/hw/9pfs/virtio-9p-device.c
> > index 50dc93091d..1ec48fc9e0 100644
> > --- a/hw/9pfs/virtio-9p-device.c
> > +++ b/hw/9pfs/virtio-9p-device.c
> > @@ -243,6 +243,7 @@ static void virtio_9p_device_unrealize(DeviceState
> *dev)
> > V9fsVirtioState *v = VIRTIO_9P(dev);
> >      V9fsState *s = &v->state;
> >
> > +    v9fs_reset(s);
> >      virtio_delete_queue(v->vq);
> >      virtio_cleanup(vdev);
> >      v9fs_device_unrealize_common(s);
>
>
>

Reply via email to