[EXTERNAL] [PATCH 2/2] net/mana: fix double free of mbuf on Rx WQE post failure

Long Li longli at microsoft.com
Thu Aug 6 02:31:57 CEST 2026


> mana_post_rx_wqe() frees the mbuf when mana_alloc_pmd_mr() fails, but the
> caller already frees the un-posted range starting at that same mbuf via
> rte_pktmbuf_free_bulk(&mbufs[i], batch_count - i), so the mbuf is returned to
> the mempool twice and can be handed out to two consumers at once.
> 
> The free was correct before the bulk allocation rework, when this function
> allocated the mbuf itself. Now that the caller owns it, leave the mbuf to the
> caller on every error path.
> 
> Fixes: eeb37809601b ("net/mana: use bulk mbuf allocation for Rx WQEs")
> Cc: stable at dpdk.org
> Signed-off-by: Rita Ruvinsky <rita.ruvinsky at weka.io>

Reviewed-by: Long Li <longli at microsoft.com>


> ---
>  drivers/net/mana/rx.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/net/mana/rx.c b/drivers/net/mana/rx.c index
> f196d43aee..2bca004dfa 100644
> --- a/drivers/net/mana/rx.c
> +++ b/drivers/net/mana/rx.c
> @@ -68,10 +68,10 @@ mana_post_rx_wqe(struct mana_rxq *rxq, struct
> rte_mbuf *mbuf)
>         int ret;
>         struct mana_mr_cache *mr;
> 
> +       /* Don't free mbuf on error: the caller bulk-frees it from
> + &mbufs[i]. */
>         mr = mana_alloc_pmd_mr(&rxq->mr_btree, priv, mbuf);
>         if (!mr) {
>                 DP_LOG(ERR, "failed to register RX MR");
> -               rte_pktmbuf_free(mbuf);
>                 return -ENOMEM;
>         }
> 
> --
> 2.43.0



More information about the dev mailing list