summary refs log tree commit diff stats
path: root/gitlab/issues_text/target_missing/host_missing/accel_missing/1381
diff options
context:
space:
mode:
Diffstat (limited to 'gitlab/issues_text/target_missing/host_missing/accel_missing/1381')
-rw-r--r--gitlab/issues_text/target_missing/host_missing/accel_missing/13813
1 files changed, 3 insertions, 0 deletions
diff --git a/gitlab/issues_text/target_missing/host_missing/accel_missing/1381 b/gitlab/issues_text/target_missing/host_missing/accel_missing/1381
new file mode 100644
index 000000000..cd14a192f
--- /dev/null
+++ b/gitlab/issues_text/target_missing/host_missing/accel_missing/1381
@@ -0,0 +1,3 @@
+plugins: plugin_mem_cbs is not consistently NULL'ed when returning from execution
+Description of problem:
+This is an invariant that we should have been checking for; when returning from execution, cpu->plugin_mem_cbs should be NULL. Otherwise we open a door for a use-after-free; admittedly this door isn't that large (it requires a tb_flush to occur while we have the dangling plugin_mem_cbs), but at least one plugin user has encountered this problem: https://lists.nongnu.org/archive/html/qemu-devel/2022-11/msg02703.html