[PATCH] net/txgbe: fix use-after-free in flow destroy

Stephen Hemminger stephen at networkplumber.org
Thu Sep 10 17:53:34 CEST 2026


On Thu, 10 Sep 2026 21:39:41 +0800
Zhang Tengfei <zhtfdev at gmail.com> wrote:

> TAILQ_FOREACH advances via the current node's next pointer. Removing
> and freeing that node inside the loop reads freed memory on the next
> iteration.
> 
> Find the matching entry first, then remove it after the loop.
> 
> Fixes: e342da2d438f ("net/txgbe: support destroying consistent filter")
> Cc: stable at dpdk.org
> 

OK, another option would be to use TAILQ_FOREACH_SAFE which several other
drivers do. I have a patch series to cleanup the queue macros but waiting.


More information about the stable mailing list