Re: [Qemu-devel] [PATCH 4/4] migration: fix use-after-free of to_dst_file

2017-02-28 Thread Dr. David Alan Gilbert
* Vladimir Sementsov-Ogievskiy (vsement...@virtuozzo.com) wrote: > hmp_savevm calls qemu_savevm_state(f), which sets to_dst_file=f in > global migration state. Then hmp_savevm closes f (g_free called). > > Next access to to_dst_file in migration state (for example, > qmp_migrate_set_speed) will us

Re: [Qemu-devel] [PATCH 4/4] migration: fix use-after-free of to_dst_file

2017-02-27 Thread Dr. David Alan Gilbert
* Vladimir Sementsov-Ogievskiy (vsement...@virtuozzo.com) wrote: > hmp_savevm calls qemu_savevm_state(f), which sets to_dst_file=f in > global migration state. Then hmp_savevm closes f (g_free called). > > Next access to to_dst_file in migration state (for example, > qmp_migrate_set_speed) will us

[Qemu-devel] [PATCH 4/4] migration: fix use-after-free of to_dst_file

2017-02-25 Thread Vladimir Sementsov-Ogievskiy
hmp_savevm calls qemu_savevm_state(f), which sets to_dst_file=f in global migration state. Then hmp_savevm closes f (g_free called). Next access to to_dst_file in migration state (for example, qmp_migrate_set_speed) will use it after it was freed. Signed-off-by: Vladimir Sementsov-Ogievskiy ---