qemu-trivial
[Top][All Lists]
Advanced

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Qemu-trivial] [PATCH v6 01/10] l2cap: fix access freed memory


From: Michael S. Tsirkin
Subject: Re: [Qemu-trivial] [PATCH v6 01/10] l2cap: fix access freed memory
Date: Thu, 14 Aug 2014 12:19:52 +0200

On Thu, Aug 14, 2014 at 03:29:12PM +0800, zhanghailiang wrote:
> Pointer 'ch' will be used in function 'l2cap_channel_open_req_msg' after
> it was previously freed in 'l2cap_channel_open'.
> Assigned it to NULL after it is freed.

Reviewed-by: Michael S. Tsirkin <address@hidden>


> 
> Reviewed-by: Alex Bennée <address@hidden>
> Signed-off-by: zhanghailiang <address@hidden>
> ---
>  hw/bt/l2cap.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/hw/bt/l2cap.c b/hw/bt/l2cap.c
> index 2301d6f..591e047 100644
> --- a/hw/bt/l2cap.c
> +++ b/hw/bt/l2cap.c
> @@ -429,7 +429,7 @@ static struct l2cap_chan_s *l2cap_channel_open(struct 
> l2cap_instance_s *l2cap,
>                  status = L2CAP_CS_NO_INFO;
>              } else {
>                  g_free(ch);
> -
> +                ch = NULL;
>                  result = L2CAP_CR_NO_MEM;
>                  status = L2CAP_CS_NO_INFO;
>              }
> -- 
> 1.7.12.4
> 



reply via email to

[Prev in Thread] Current Thread [Next in Thread]