]> git.ipfire.org Git - thirdparty/libvirt.git/commitdiff
qemu: Fix job usage in qemuDomainBlockJobImpl
authorJiri Denemark <jdenemar@redhat.com>
Fri, 20 Dec 2013 14:04:09 +0000 (15:04 +0100)
committerGuido Günther <agx@sigxcpu.org>
Sat, 11 Jan 2014 12:40:28 +0000 (13:40 +0100)
CVE-2013-6458

Every API that is going to begin a job should do that before fetching
data from vm->def.

Conflicts:
        src/qemu/qemu_driver.c

(cherry picked from commit f93d2caa070f6197ab50d372d286018b0ba6bbd8)

src/qemu/qemu_driver.c

index b17aa09ae1071c8a5f64bcfc723459dfcbe03a61..f810275894bb942e9ed388e0c74b3650d25aad59 100644 (file)
@@ -11749,11 +11749,6 @@ qemuDomainBlockJobImpl(virDomainPtr dom, const char *path, const char *base,
         goto cleanup;
     }
 
-    device = qemuDiskPathToAlias(vm, path, &idx);
-    if (!device)
-        goto cleanup;
-    disk = vm->def->disks[idx];
-
     if (qemuDomainObjBeginJobWithDriver(driver, vm, QEMU_JOB_MODIFY) < 0)
         goto cleanup;
 
@@ -11763,6 +11758,11 @@ qemuDomainBlockJobImpl(virDomainPtr dom, const char *path, const char *base,
         goto endjob;
     }
 
+    device = qemuDiskPathToAlias(vm, path, &idx);
+    if (!device)
+        goto endjob;
+    disk = vm->def->disks[idx];
+
     qemuDomainObjEnterMonitorWithDriver(driver, vm);
     /* XXX - libvirt should really be tracking the backing file chain
      * itself, and validating that base is on the chain, rather than