Commit b3dd1b8c authored by Michael S. Tsirkin's avatar Michael S. Tsirkin Committed by Luiz Capitulino

monitor: fix use after free

The function monitor_fdset_dup_fd_find_remove() references member of
'mon_fdset' which - when remove flag is set - may be freed in function
remove is set by monitor_fdset_dup_fd_remove which in practice
does not need the returned value, so make it void,
and return -1 from monitor_fdset_dup_fd_find_remove.
Reported-by: default avatarzhanghailiang <>
Signed-off-by: default avatarMichael S. Tsirkin <>
Signed-off-by: default avatarLuiz Capitulino <>
parent 2928207a
......@@ -64,7 +64,7 @@ AddfdInfo *monitor_fdset_add_fd(int fd, bool has_fdset_id, int64_t fdset_id,
Error **errp);
int monitor_fdset_get_fd(int64_t fdset_id, int flags);
int monitor_fdset_dup_fd_add(int64_t fdset_id, int dup_fd);
int monitor_fdset_dup_fd_remove(int dup_fd);
void monitor_fdset_dup_fd_remove(int dup_fd);
int monitor_fdset_dup_fd_find(int dup_fd);
#endif /* !MONITOR_H */
......@@ -2542,8 +2542,10 @@ static int monitor_fdset_dup_fd_find_remove(int dup_fd, bool remove)
if (QLIST_EMPTY(&mon_fdset->dup_fds)) {
return -1;
} else {
return mon_fdset->id;
return mon_fdset->id;
......@@ -2555,9 +2557,9 @@ int monitor_fdset_dup_fd_find(int dup_fd)
return monitor_fdset_dup_fd_find_remove(dup_fd, false);
int monitor_fdset_dup_fd_remove(int dup_fd)
void monitor_fdset_dup_fd_remove(int dup_fd)
return monitor_fdset_dup_fd_find_remove(dup_fd, true);
monitor_fdset_dup_fd_find_remove(dup_fd, true);
int monitor_handle_fd_param(Monitor *mon, const char *fdname)
#include "qemu-common.h"
#include "monitor/monitor.h"
int monitor_fdset_dup_fd_remove(int dupfd)
void monitor_fdset_dup_fd_remove(int dupfd)
return -1;
