From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:51797) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1aeOgo-0001rq-Jq for qemu-devel@nongnu.org; Fri, 11 Mar 2016 10:09:19 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1aeOgi-0000ES-RD for qemu-devel@nongnu.org; Fri, 11 Mar 2016 10:09:18 -0500 Received: from mx1.redhat.com ([209.132.183.28]:55190) by eggs.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1aeOgi-0000EL-MJ for qemu-devel@nongnu.org; Fri, 11 Mar 2016 10:09:12 -0500 Date: Fri, 11 Mar 2016 17:09:09 +0200 From: "Michael S. Tsirkin" Message-ID: <1457708548-14093-29-git-send-email-mst@redhat.com> References: <1457708548-14093-1-git-send-email-mst@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Disposition: inline In-Reply-To: <1457708548-14093-1-git-send-email-mst@redhat.com> Content-Transfer-Encoding: quoted-printable Subject: [Qemu-devel] [PULL 28/53] qemu-char: avoid potential double-free List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Cc: Peter Maydell , Paolo Bonzini , Eduardo Habkost , =?us-ascii?B?PT9VVEYtOD9xP01hcmMtQW5kcj1DMz1BOT0yMEx1cmVhdT89?= From: Marc-Andr=E9 Lureau If tcp_set_msgfds() is called several time with NULL fds, this could lead to double-free. Signed-off-by: Marc-Andr=E9 Lureau Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin --- qemu-char.c | 1 + 1 file changed, 1 insertion(+) diff --git a/qemu-char.c b/qemu-char.c index e0147f3..fc4611d 100644 --- a/qemu-char.c +++ b/qemu-char.c @@ -2697,6 +2697,7 @@ static int tcp_set_msgfds(CharDriverState *chr, int= *fds, int num) } /* clear old pending fd array */ g_free(s->write_msgfds); + s->write_msgfds =3D NULL; =20 if (num) { s->write_msgfds =3D g_new(int, num); --=20 MST