From: David Gibson Date: Wed, 6 Mar 2019 03:05:59 +0000 (+1100) Subject: virtio-balloon: Don't mismatch g_malloc()/free (CID 1399146) X-Git-Url: http://git.maquefel.me/?a=commitdiff_plain;h=301cf2a8dd5024aa5bbdc6bd3e121174bbfc2957;p=qemu.git virtio-balloon: Don't mismatch g_malloc()/free (CID 1399146) ed48c59875b6 "virtio-balloon: Safely handle BALLOON_PAGE_SIZE < host page size" introduced a new temporary data structure which tracks 4kiB chunks which have been inserted into the balloon by the guest but don't yet form a full host page which we can discard. Unfortunately, I had a thinko and allocated that structure with g_malloc0() but freed it with a plain free() rather than g_free(). This corrects the problem. Fixes: ed48c59875b6 Reported-by: Peter Maydell Signed-off-by: David Gibson Message-Id: <20190306030601.21986-2-david@gibson.dropbear.id.au> Reviewed-by: Michael S. Tsirkin Signed-off-by: Michael S. Tsirkin Reviewed-by: David Hildenbrand --- diff --git a/hw/virtio/virtio-balloon.c b/hw/virtio/virtio-balloon.c index b614552352..1859724a36 100644 --- a/hw/virtio/virtio-balloon.c +++ b/hw/virtio/virtio-balloon.c @@ -82,7 +82,7 @@ static void balloon_inflate_page(VirtIOBalloon *balloon, /* We've partially ballooned part of a host page, but now * we're trying to balloon part of a different one. Too hard, * give up on the old partial page */ - free(balloon->pbp); + g_free(balloon->pbp); balloon->pbp = NULL; } @@ -107,7 +107,7 @@ static void balloon_inflate_page(VirtIOBalloon *balloon, * has already reported them, and failing to discard a balloon * page is not fatal */ - free(balloon->pbp); + g_free(balloon->pbp); balloon->pbp = NULL; } }