From: Daniel P. Berrange Date: Wed, 27 Apr 2016 10:04:52 +0000 (+0100) Subject: io: avoid double-free when closing QIOChannelBuffer X-Git-Url: http://git.maquefel.me/?a=commitdiff_plain;h=d656ec5ea823bcdb59b6512cb73b3f2f97a8308f;p=qemu.git io: avoid double-free when closing QIOChannelBuffer The QIOChannelBuffer's close implementation will free the internal data buffer. It failed to reset the pointer to NULL though, so when the object is later finalized it will free it a second time with predictable crash. Reviewed-by: Dr. David Alan Gilbert Signed-off-by: Daniel P. Berrange Reviewed-by: Juan Quintela Message-Id: <1461751518-12128-3-git-send-email-berrange@redhat.com> Signed-off-by: Amit Shah --- diff --git a/io/channel-buffer.c b/io/channel-buffer.c index 3e5117bf28..43d795976d 100644 --- a/io/channel-buffer.c +++ b/io/channel-buffer.c @@ -140,6 +140,7 @@ static int qio_channel_buffer_close(QIOChannel *ioc, QIOChannelBuffer *bioc = QIO_CHANNEL_BUFFER(ioc); g_free(bioc->data); + bioc->data = NULL; bioc->capacity = bioc->usage = bioc->offset = 0; return 0;