@samitouri / QOSamiQemu / commits / 2741d2cc39

target/i386: fix NULL pointer dereference in legacy-cache=off handling

The check that xcc->model is not NULL occurs after it is dereferenced inside x86_cpu_get_versioned_cache_info(), so something like `-cpu host,legacy-cache=off` leads to a segfault rather than an error. This patch fixes that. Fixes: cca0a000d06f897411a8a ("target/i386: allow versioned CPUs to specify new cache_info") Signed-off-by: Sergei Heifetz <heifetz@yandex-team.com> Reviewed-by: Vladimir Sementsov-Ogievskiy <vsementsov@yandex-team.ru> Reviewed-by: Zhao Liu <zhao1.liu@intel.com> Reviewed-by: Michael Tokarev <mjt@tls.msk.ru> [Mjt: simplify the following condition too] Signed-off-by: Michael Tokarev <mjt@tls.msk.ru>

Sergei Heifetz committed Mar 5, 2026 at 11:04 UTC 2741d2cc39033929485b50792a85b5c794b1c903
1 file changed +4 -3
target/i386/cpu.c
+4 -3
@@ -10107,10 +10107,11 @@ static void x86_cpu_realizefn(DeviceState *dev, Error **errp)
10107
10108 /* Cache information initialization */
10109 if (!cpu->legacy_cache) {
10110 - const CPUCaches *cache_info =
10111 - x86_cpu_get_versioned_cache_info(cpu, xcc->model);
10110 + const CPUCaches *cache_info = xcc->model
10111 + ? x86_cpu_get_versioned_cache_info(cpu, xcc->model)
10112 + : NULL;
10113
10113 - if (!xcc->model || !cache_info) {
10114 + if (!cache_info) {
10115 g_autofree char *name = x86_cpu_class_get_model_name(xcc);
10116 error_setg(errp,
10117 "CPU model '%s' doesn't support legacy-cache=off", name);