[openib-general] Re: [PATCH] ipoib_mcast_restart_task

Michael S. Tsirkin mst at mellanox.co.il
Wed Apr 5 09:53:03 PDT 2006


Quoting r. Roland Dreier <rdreier at cisco.com>:
> Subject: Re: [PATCH] ipoib_mcast_restart_task
> 
>     Michael> Not sure I read you. It'd still be use after free, won't it?
> 
> It's definitely a bug.  But it doesn't explain the specific oops we
> saw.

The mcast pointer comes from stack.  Surely we could have use after free in
ipoib_mcast_join_complete trigger data corruption on stack and then trip on it?

-- 
MST



More information about the general mailing list