[openib-general] Re: [PATCH] ipoib_mcast_restart_task

Roland Dreier rdreier at cisco.com
Wed Apr 5 09:57:29 PDT 2006


    Michael> The mcast pointer comes from stack.  Surely we could have
    Michael> use after free in ipoib_mcast_join_complete trigger data
    Michael> corruption on stack and then trip on it?

Now you're confusing me.  Isn't the mcast pointer kmalloc()ed?

 - R.



More information about the general mailing list