blob: 69f706a9ece234784e1d5f43d4bd8e0c64f6fee2 (
plain) (
blame)
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
|
graphic: 0.580
device: 0.525
semantic: 0.439
ppc: 0.359
network: 0.342
vnc: 0.315
performance: 0.295
i386: 0.213
architecture: 0.175
x86: 0.135
TCG: 0.132
VMM: 0.125
debug: 0.124
kernel: 0.124
mistranslation: 0.123
boot: 0.121
socket: 0.111
risc-v: 0.110
arm: 0.100
KVM: 0.084
peripherals: 0.066
permissions: 0.056
files: 0.056
virtual: 0.051
hypervisor: 0.047
register: 0.042
PID: 0.041
user-level: 0.030
assembly: 0.015
Possible dereference of NULL in block/qapi.c
Description of problem:
qdict_get can return NULL if the "data" key is not found in the obj dictionary. Then if NULL is passed to the qobject_is_empty_dump function, it will be dereferenced when calling the qobject_type function.
https://github.com/qemu/qemu/blob/92ec7805190313c9e628f8fc4eb4f932c15247bd/block/qapi.c#L891-L892
I think that data check for NULL should be added.
Found by Linux Verification Center (portal.linuxtesting.ru) with SVACE.
Author A. Burke.
|