This fixes a possible read beyond the end of the temporary buffers used for comparing data in the old and the new backing file.
Signed-off-by: Kevin Wolf <kw...@redhat.com> --- qemu-img.c | 2 +- 1 files changed, 1 insertions(+), 1 deletions(-) diff --git a/qemu-img.c b/qemu-img.c index 250d892..258dc62 100644 --- a/qemu-img.c +++ b/qemu-img.c @@ -1225,7 +1225,7 @@ static int img_rebase(int argc, char **argv) int pnum; if (compare_sectors(buf_old + written * 512, - buf_new + written * 512, n, &pnum)) + buf_new + written * 512, n - written, &pnum)) { ret = bdrv_write(bs, sector + written, buf_old + written * 512, pnum); -- 1.6.6