Re: [Bug 1888606] [NEW] Heap-use-after-free in virtio_gpu_ctrl_response

2020-08-03 Thread Li Qiang
Gerd Hoffmann 于2020年8月3日周一 下午2:57写道: > > Hi, > > > > The ASAN trace: > > > ==29798==ERROR: AddressSanitizer: heap-use-after-free on address > > > 0x60d050e8 at pc 0x560629814761 bp 0x7ffe916eb1e0 sp 0x7ffe916eb1d8 > > > READ of size 8 at 0x60d050e8 thread T0 > > > #0 0x560629814760

Re: [Bug 1888606] [NEW] Heap-use-after-free in virtio_gpu_ctrl_response

2020-08-03 Thread Alexander Bulekov
Hi Gerd, Strange... After applying your patch, I re-ran the reproducer, but I still see the same crash. -Alex On 200803 0856, Gerd Hoffmann wrote: > Hi, > > > > The ASAN trace: > > > ==29798==ERROR: AddressSanitizer: heap-use-after-free on address > > > 0x60d050e8 at pc 0x560629814761 bp 0

Re: [Bug 1888606] [NEW] Heap-use-after-free in virtio_gpu_ctrl_response

2020-08-02 Thread Gerd Hoffmann
Hi, > > The ASAN trace: > > ==29798==ERROR: AddressSanitizer: heap-use-after-free on address > > 0x60d050e8 at pc 0x560629814761 bp 0x7ffe916eb1e0 sp 0x7ffe916eb1d8 > > READ of size 8 at 0x60d050e8 thread T0 > > #0 0x560629814760 in virtio_gpu_ctrl_response > > /home/alxndr/Develop

Re: [Bug 1888606] [NEW] Heap-use-after-free in virtio_gpu_ctrl_response

2020-07-23 Thread Alexander Bulekov
On 200723 1351, Li Qiang wrote: > Alexander Bulekov <1888...@bugs.launchpad.net> 于2020年7月23日周四 下午1:02写道: > > > > Public bug reported: > > > > Hello, > > Here is a reproducer (build with --enable-sanitizers): > > cat << EOF | ./i386-softmmu/qemu-system-i386 -nographic -M pc -nodefaults > > -m 512M

Re: [Bug 1888606] [NEW] Heap-use-after-free in virtio_gpu_ctrl_response

2020-07-23 Thread Alexander Bulekov
CC-ing virtio-gpu Maintainers. On 200723 0455, Alexander Bulekov wrote: > Public bug reported: > > Hello, > Here is a reproducer (build with --enable-sanitizers): > cat << EOF | ./i386-softmmu/qemu-system-i386 -nographic -M pc -nodefaults -m > 512M -device virtio-vga -qtest stdio > outl 0xcf8 0x

Re: [Bug 1888606] [NEW] Heap-use-after-free in virtio_gpu_ctrl_response

2020-07-22 Thread Li Qiang
Alexander Bulekov <1888...@bugs.launchpad.net> 于2020年7月23日周四 下午1:02写道: > > Public bug reported: > > Hello, > Here is a reproducer (build with --enable-sanitizers): > cat << EOF | ./i386-softmmu/qemu-system-i386 -nographic -M pc -nodefaults -m > 512M -device virtio-vga -qtest stdio > outl 0xcf8 0x8

[Bug 1888606] [NEW] Heap-use-after-free in virtio_gpu_ctrl_response

2020-07-22 Thread Alexander Bulekov
Public bug reported: Hello, Here is a reproducer (build with --enable-sanitizers): cat << EOF | ./i386-softmmu/qemu-system-i386 -nographic -M pc -nodefaults -m 512M -device virtio-vga -qtest stdio outl 0xcf8 0x80001018 outl 0xcfc 0xe080 outl 0xcf8 0x80001020 outl 0xcf8 0x80001004 outw 0xcfc 0