diff options
| author | Vladimir Sementsov-Ogievskiy | 2017-02-25 20:31:55 +0100 |
|---|---|---|
| committer | Dr. David Alan Gilbert | 2017-02-28 12:30:23 +0100 |
| commit | f9c8caa04f7f2bed12dc5a4d7e92a59fe6677b37 (patch) | |
| tree | 1a783b2de80762744924e7e74e18a2bce393b30b /include/migration | |
| parent | migration: Update docs to discourage version bumps (diff) | |
| download | qemu-f9c8caa04f7f2bed12dc5a4d7e92a59fe6677b37.tar.gz qemu-f9c8caa04f7f2bed12dc5a4d7e92a59fe6677b37.tar.xz qemu-f9c8caa04f7f2bed12dc5a4d7e92a59fe6677b37.zip | |
migration: fix use-after-free of to_dst_file
hmp_savevm calls qemu_savevm_state(f), which sets to_dst_file=f in
global migration state. Then hmp_savevm closes f (g_free called).
Next access to to_dst_file in migration state (for example,
qmp_migrate_set_speed) will use it after it was freed.
Signed-off-by: Vladimir Sementsov-Ogievskiy <vsementsov@virtuozzo.com>
Reviewed-by: Dr. David Alan Gilbert <dgilbert@redhat.com>
Message-Id: <20170225193155.447462-5-vsementsov@virtuozzo.com>
Signed-off-by: Dr. David Alan Gilbert <dgilbert@redhat.com>
Diffstat (limited to 'include/migration')
0 files changed, 0 insertions, 0 deletions
