[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [PATCH for-4.21 2/6] tools/libxl: avoid freeing stack rubble in libxl__json_object_to_json()


  • To: Roger Pau Monne <roger.pau@xxxxxxxxxx>, <xen-devel@xxxxxxxxxxxxxxxxxxxx>
  • From: Jason Andryuk <jason.andryuk@xxxxxxx>
  • Date: Wed, 15 Oct 2025 14:50:15 -0400
  • Arc-authentication-results: i=1; mx.microsoft.com 1; spf=pass (sender ip is 165.204.84.17) smtp.rcpttodomain=citrix.com smtp.mailfrom=amd.com; dmarc=pass (p=quarantine sp=quarantine pct=100) action=none header.from=amd.com; dkim=none (message not signed); arc=none (0)
  • Arc-message-signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector10001; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=kzYYdd6yASB1df4nN5ksjUGYlWqBQJBhElXxtuZkeZs=; b=y4b+EHrbwpAbFWALRgwrMgwj54dntblGXbJMlI2e1U4aBPNK06hY9QsyyZy5GsFkKq2ow8IVCikSAmA+evXak1vxfTMZnjBknDy5tvERsn3f4Fnc9Ca1LOIdBYCIJjAoe8yiHLOJ74bayG4UKWjn03ClMjyT+qBKc/uREWLoUPdLrSJxQZyvdduCo93EAOddndUMhv5LF6isVh8p/ex07XI79jRAjx7sJfYIoB4Vx+aelAOuIRnRHImvjiIYDw0iCJYifVITa0nLcQmgJpnBvye5P5vSwhklNMpLGuybJMMPgBnDQHFl36BsPySrZjnME5v8sfuiyDi385/2Zswgtg==
  • Arc-seal: i=1; a=rsa-sha256; s=arcselector10001; d=microsoft.com; cv=none; b=DHmcBfEoN3x253HX4Zu/ewgko+ENrnEqFUJGXgjk9F+UiWOUXajqxOcEfDH76JpivX2lUex3Al7tSUyI5z5MfJ1tD3V94limW8DXELXfnSnORS+WOtumqptS/q4BpHlTQ9Qb+PXcYLnxKRbezJgwJ1Zzf+64zyCOxW+4K0vY6gv38OeeTiDG5usUP9YjE8Dakj054PtThLVakpWw6AcfkGFxo6sschCflzVwqNkp/V+H/R8zm+kZCmyHZwCnFhLrG0+oQ0GUEhr9mFzxIjksRxygiwZR+9kAyfJqkjSA8/Hg742eB5wsmZcXSNUNHpBOGVd7uMnhemFL9MAj6/Cx7g==
  • Cc: <oleksii.kurochko@xxxxxxxxx>, Anthony PERARD <anthony.perard@xxxxxxxxxx>, Juergen Gross <jgross@xxxxxxxx>
  • Delivery-date: Wed, 15 Oct 2025 18:50:39 +0000
  • List-id: Xen developer discussion <xen-devel.lists.xenproject.org>

On 2025-10-15 09:40, Roger Pau Monne wrote:
It's possible for libxl__json_object_to_json_object() to not set the passed
jso_out parameter, hence initialize it in libxl__json_object_to_json() to
avoid freeing an uninitialized pointer in case of failure.

Reported by XenServer internal Coverity instance.

Fixes: 75fa670e582c ("libxl: Convert libxl__json_object_to_json() to 
json_object")
Signed-off-by: Roger Pau Monné <roger.pau@xxxxxxxxxx>

Reviewed-by: Jason Andryuk <jason.andryuk@xxxxxxx>



 


Rackspace

Lists.xenproject.org is hosted with RackSpace, monitoring our
servers 24x7x365 and backed by RackSpace's Fanatical Support®.