From mboxrd@z Thu Jan 1 00:00:00 1970 Received: from eggs.gnu.org ([140.186.70.92]:60866) by lists.gnu.org with esmtp (Exim 4.71) (envelope-from ) id 1RKqT6-0001sg-Pr for qemu-devel@nongnu.org; Mon, 31 Oct 2011 07:55:57 -0400 Received: from Debian-exim by eggs.gnu.org with spam-scanned (Exim 4.71) (envelope-from ) id 1RKqT5-0007No-1R for qemu-devel@nongnu.org; Mon, 31 Oct 2011 07:55:56 -0400 Date: Mon, 31 Oct 2011 11:55:52 +0000 From: Stefan Hajnoczi Message-ID: <20111031115552.GC10693@stefanha-thinkpad.localdomain> References: <1319814422-17952-1-git-send-email-armbru@redhat.com> MIME-Version: 1.0 Content-Type: text/plain; charset=us-ascii Content-Disposition: inline In-Reply-To: <1319814422-17952-1-git-send-email-armbru@redhat.com> Subject: Re: [Qemu-devel] [PATCH] acl: Fix use after free in qemu_acl_reset() List-Id: List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , To: Markus Armbruster Cc: qemu-trivial@nongnu.org, qemu-devel@nongnu.org On Fri, Oct 28, 2011 at 05:07:02PM +0200, Markus Armbruster wrote: > Reproducer: > > $ MALLOC_PERTURB_=234 qemu-system-x86_64 -vnc :0,acl,sasl [...] > QEMU 0.15.50 monitor - type 'help' for more information > (qemu) acl_add vnc.username fred allow > acl: added rule at position 1 > (qemu) acl_reset vnc.username > Segmentation fault (core dumped) > > Spotted by Coverity. > > Signed-off-by: Markus Armbruster > --- > acl.c | 4 ++-- > 1 files changed, 2 insertions(+), 2 deletions(-) Thanks, applied to the trivial patches -next tree: http://repo.or.cz/w/qemu/stefanha.git/shortlog/refs/heads/trivial-patches-next Stefan