Re: [PATCH] target/i386: fix NULL pointer dereference in legacy-cache=off handling

Michael Tokarev <[email protected]>
Newsgroups org.nongnu.qemu-trivial,org.nongnu.qemu-devel
Message-ID <[email protected]>
On 05.03.2026 09:04, Sergei Heifetz wrote:
> The check that xcc->model is not NULL occurs after it is dereferenced
> inside x86_cpu_get_versioned_cache_info(), so something like
> `-cpu host,legacy-cache=off` leads to a segfault rather than an error.
> This patch fixes that.
> 
> Fixes: cca0a000d06f897411a8a ("target/i386: allow versioned CPUs to specify new cache_info")
> Signed-off-by: Sergei Heifetz <[email protected]>
> ---
>   target/i386/cpu.c | 5 +++--
>   1 file changed, 3 insertions(+), 2 deletions(-)
> 
> diff --git a/target/i386/cpu.c b/target/i386/cpu.c
> index 01b64940b1..00645e1149 100644
> --- a/target/i386/cpu.c
> +++ b/target/i386/cpu.c
> @@ -10023,8 +10023,9 @@ static void x86_cpu_realizefn(DeviceState *dev, Error **errp)
>   
>       /* Cache information initialization */
>       if (!cpu->legacy_cache) {
> -        const CPUCaches *cache_info =
> -            x86_cpu_get_versioned_cache_info(cpu, xcc->model);
> +        const CPUCaches *cache_info = xcc->model
> +            ? x86_cpu_get_versioned_cache_info(cpu, xcc->model)
> +            : NULL;
>   
>           if (!xcc->model || !cache_info) {
>               g_autofree char *name = x86_cpu_class_get_model_name(xcc);

With this cache_info init, the condition in the next line can be
simplified to just (!cache_info).  Dunno if it's worth the effort
though.  I can fold this change into the patch at apply time if you're
ok with it.

Thanks,

/mjt
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.