From: Josh Durgin <josh.dur...@dreamhost.com> The caller expects psn_tab to be NULL when there are no snapshots or an error occurs. This results in calling g_free on an invalid address.
Reported-by: Oliver Francke <oli...@filoo.de> Signed-off-by: Josh Durgin <josh.dur...@dreamhost.com> Signed-off-by: Kevin Wolf <kw...@redhat.com> --- block/rbd.c | 3 ++- 1 files changed, 2 insertions(+), 1 deletions(-) diff --git a/block/rbd.c b/block/rbd.c index 312584a..7a2384c 100644 --- a/block/rbd.c +++ b/block/rbd.c @@ -805,7 +805,7 @@ static int qemu_rbd_snap_list(BlockDriverState *bs, } while (snap_count == -ERANGE); if (snap_count <= 0) { - return snap_count; + goto done; } sn_tab = g_malloc0(snap_count * sizeof(QEMUSnapshotInfo)); @@ -824,6 +824,7 @@ static int qemu_rbd_snap_list(BlockDriverState *bs, } rbd_snap_list_end(snaps); + done: *psn_tab = sn_tab; return snap_count; } -- 1.7.6.4