On Thu, Aug 20, 2026 at 02:39:52PM +0300, Andrey Drobyshev wrote:
A device which only went through vhost_dev_init_backend() has its VQs not yet initialized, so vq->dev is NULL and vhost_virtqueue_cleanup() would crash dereferencing it. Check vq->dev before use, so that vhost_dev_cleanup() can be called to release a device whose full vhost_dev_init() never ran or failed along the way.
Is this a fix for a current issue, a defensive programming measure, or something that might happen with future patches?
Stefano
Signed-off-by: Andrey Drobyshev <[email protected]> --- hw/virtio/vhost.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/hw/virtio/vhost.c b/hw/virtio/vhost.c index f9b54c46f93..2bb9a23fee4 100644 --- a/hw/virtio/vhost.c +++ b/hw/virtio/vhost.c @@ -1648,7 +1648,7 @@ fail_call: static void vhost_virtqueue_cleanup(struct vhost_virtqueue *vq) { event_notifier_cleanup(&vq->masked_notifier); - if (vq->dev->vhost_ops->vhost_set_vring_err) { + if (vq->dev && vq->dev->vhost_ops->vhost_set_vring_err) { event_notifier_set_handler(&vq->error_notifier, NULL); event_notifier_cleanup(&vq->error_notifier); } -- 2.47.1
