kvm tools: Fix another use-after-free in shutdown sequence

Valgrind spotted another issue:

  ==2343== Invalid read of size 8
  ==2343==    at 0x408EAD: kvm__pause (kvm.c:529)
  ==2343==    by 0x407E07: ioport__unregister (ioport.c:100)
  ==2343==    by 0x409537: pci__exit (pci.c:210)
  ==2343==    by 0x406303: kvm_cmd_run (builtin-run.c:1314)
  ==2343==    by 0x410670: handle_command (kvm-cmd.c:84)
  ==2343==    by 0x3DE682139C: (below main) (in /lib64/libc-2.14.so)
  ==2343==  Address 0x4c30ca0 is 0 bytes inside a block of size 520 free'd
  ==2343==    at 0x4A055FE: free (vg_replace_malloc.c:366)
  ==2343==    by 0x406293: kvm_cmd_run (builtin-run.c:1292)
  ==2343==    by 0x410670: handle_command (kvm-cmd.c:84)
  ==2343==    by 0x3DE682139C: (below main) (in /lib64/libc-2.14.so)

Signed-off-by: Pekka Enberg <penberg@kernel.org>
This commit is contained in:
Pekka Enberg
2015-06-01 16:39:51 +01:00
committed by Will Deacon
parent f740cfb823
commit 49777800ce
+2 -1
View File
@@ -1289,7 +1289,6 @@ static void kvm_cmd_run_exit(int guest_ret)
r = disk_image__close_all(kvm->disks, image_count);
if (r < 0)
pr_warning("disk_image__close_all() failed with error %d\n", r);
free(kvm_cpus);
r = serial8250__exit(kvm);
if (r < 0)
@@ -1319,6 +1318,8 @@ static void kvm_cmd_run_exit(int guest_ret)
if (r < 0)
pr_warning("pci__exit() failed with error %d\n", r);
free(kvm_cpus);
if (guest_ret == 0)
printf("\n # KVM session ended normally.\n");
}