mirror of
https://github.com/clearlinux/kvmtool.git
synced 2026-10-04 07:48:28 +00:00
kvm tools, x86: Fix use after free in irq__exit()
Valgrind spotted this issue with KVM tool shutdown: ==1823== Invalid read of size 8 ==1823== at 0x410DD0: rb_next (rbtree.c:390) ==1823== by 0x417376: irq__exit (irq.c:182) ==1823== by 0x406230: kvm_cmd_run (builtin-run.c:1275) ==1823== by 0x410670: handle_command (kvm-cmd.c:84) ==1823== by 0x3DE682139C: (below main) (in /lib64/libc-2.14.so) ==1823== Address 0x4f7cca0 is 0 bytes inside a block of size 48 free'd ==1823== at 0x4A055FE: free (vg_replace_malloc.c:366) ==1823== by 0x41736E: irq__exit (irq.c:192) ==1823== by 0x406230: kvm_cmd_run (builtin-run.c:1275) ==1823== by 0x410670: handle_command (kvm-cmd.c:84) ==1823== by 0x3DE682139C: (below main) (in /lib64/libc-2.14.so) Fix it up. Signed-off-by: Pekka Enberg <penberg@kernel.org>
This commit is contained in:
committed by
Will Deacon
parent
5ecfffcc52
commit
f740cfb823
@@ -179,17 +179,25 @@ int irq__exit(struct kvm *kvm)
|
||||
|
||||
free(irq_routing);
|
||||
|
||||
for (ent = rb_first(&pci_tree); ent; ent = rb_next(ent)) {
|
||||
ent = rb_first(&pci_tree);
|
||||
for (;;) {
|
||||
struct pci_dev *dev;
|
||||
struct rb_node *next;
|
||||
struct irq_line *line;
|
||||
struct list_head *node, *tmp;
|
||||
|
||||
if (!ent)
|
||||
break;
|
||||
|
||||
next = rb_next(ent);
|
||||
|
||||
dev = rb_entry(ent, struct pci_dev, node);
|
||||
list_for_each_safe(node, tmp, &dev->lines) {
|
||||
line = list_entry(node, struct irq_line, node);
|
||||
free(line);
|
||||
}
|
||||
free(dev);
|
||||
ent = next;
|
||||
}
|
||||
|
||||
return 0;
|
||||
|
||||
Reference in New Issue
Block a user