diff options
Diffstat (limited to 'results/classifier/accel-gemma3:12b/tcg/1381')
| -rw-r--r-- | results/classifier/accel-gemma3:12b/tcg/1381 | 4 |
1 files changed, 4 insertions, 0 deletions
diff --git a/results/classifier/accel-gemma3:12b/tcg/1381 b/results/classifier/accel-gemma3:12b/tcg/1381 new file mode 100644 index 00000000..d3a92891 --- /dev/null +++ b/results/classifier/accel-gemma3:12b/tcg/1381 @@ -0,0 +1,4 @@ + +plugins: plugin_mem_cbs is not consistently NULL'ed when returning from execution +Description of problem: +This is an invariant that we should have been checking for; when returning from execution, cpu->plugin_mem_cbs should be NULL. Otherwise we open a door for a use-after-free; admittedly this door isn't that large (it requires a tb_flush to occur while we have the dangling plugin_mem_cbs), but at least one plugin user has encountered this problem: https://lists.nongnu.org/archive/html/qemu-devel/2022-11/msg02703.html |