Skip to content

plugins: plugin_mem_cbs is not consistently NULL'ed when returning from execution

Description of problem

This is an invariant that we should have been checking for; when returning from execution, cpu->plugin_mem_cbs should be NULL. Otherwise we open a door for a use-after-free; admittedly this door isn't that large (it requires a tb_flush to occur while we have the dangling plugin_mem_cbs), but at least one plugin user has encountered this problem: https://lists.nongnu.org/archive/html/qemu-devel/2022-11/msg02703.html

To upload designs, you'll need to enable LFS and have an admin enable hashed storage. More information