From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([2001:4830:134:3::10]:59399) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1cjq6H-0003v2-Oa for qemu-devel@nongnu.org; Fri, 03 Mar 2017 11:30:38 -0500 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1cjq6F-0002Pt-Hi for qemu-devel@nongnu.org; Fri, 03 Mar 2017 11:30:37 -0500 Received: from mail-wm0-x241.google.com ([2a00:1450:400c:c09::241]:35404) by eggs.gnu.org with esmtps (TLS1.0:RSA_AES_128_CBC_SHA1:16) (Exim 4.71) (envelope-from ) id 1cjq6F-0002Pl-B2 for qemu-devel@nongnu.org; Fri, 03 Mar 2017 11:30:35 -0500 Received: by mail-wm0-x241.google.com with SMTP id z63so1735255wmg.2 for ; Fri, 03 Mar 2017 08:30:35 -0800 (PST) Sender: Paolo Bonzini From: Paolo Bonzini Date: Fri, 3 Mar 2017 17:30:27 +0100 Message-Id: <1488558630-21522-2-git-send-email-pbonzini@redhat.com> In-Reply-To: <1488558630-21522-1-git-send-email-pbonzini@redhat.com> References: <1488558630-21522-1-git-send-email-pbonzini@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Subject: [Qemu-devel] [PATCH 18/21] spice-char: fix segfault in char_spice_finalize List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: qemu-devel@nongnu.org Cc: Li Qiang , Li Qiang From: Li Qiang In 'qemu_chr_open_spice_vmc' if the 'psubtype' is NULL, it will call 'char_spice_finalize'. But as the SpiceChardev is not inserted in the 'spice_chars' list, the 'QLIST_REMOVE' will cause a segfault. Add a detect to avoid it. Signed-off-by: Li Qiang Message-Id: <1487665107-88004-1-git-send-email-liqiang6-s@360.cn> Reviewed-by: Marc-André Lureau Signed-off-by: Paolo Bonzini Signed-off-by: Li Qiang --- spice-qemu-char.c | 5 ++++- 1 file changed, 4 insertions(+), 1 deletion(-) diff --git a/spice-qemu-char.c b/spice-qemu-char.c index 6f46f46..4d1c76e 100644 --- a/spice-qemu-char.c +++ b/spice-qemu-char.c @@ -215,7 +215,10 @@ static void char_spice_finalize(Object *obj) SpiceChardev *s = SPICE_CHARDEV(obj); vmc_unregister_interface(s); - QLIST_REMOVE(s, next); + + if (s->next.le_prev) { + QLIST_REMOVE(s, next); + } g_free((char *)s->sin.subtype); #if SPICE_SERVER_VERSION >= 0x000c02 -- 1.8.3.1