mirror of
https://github.com/vim/vim.git
synced 2025-09-24 03:44:06 -04:00
patch 8.1.0738: using freed memory, for loop over blob leaks memory
Problem: Using freed memory, for loop over blob leaks memory. Solution: Clear pointer after freeing memory. Decrement reference count after for loop over blob.
This commit is contained in:
16
src/eval.c
16
src/eval.c
@@ -2615,6 +2615,8 @@ eval_for_line(
|
||||
clear_tv(&tv);
|
||||
else
|
||||
{
|
||||
// No need to increment the refcount, it's already set for
|
||||
// the blob being used in "tv".
|
||||
fi->fi_blob = b;
|
||||
fi->fi_bi = 0;
|
||||
}
|
||||
@@ -2684,6 +2686,8 @@ free_for_info(void *fi_void)
|
||||
list_rem_watch(fi->fi_list, &fi->fi_lw);
|
||||
list_unref(fi->fi_list);
|
||||
}
|
||||
if (fi != NULL && fi->fi_blob != NULL)
|
||||
blob_unref(fi->fi_blob);
|
||||
vim_free(fi);
|
||||
}
|
||||
|
||||
@@ -4216,9 +4220,13 @@ eval7(
|
||||
for (bp = *arg + 2; vim_isxdigit(bp[0]); bp += 2)
|
||||
{
|
||||
if (!vim_isxdigit(bp[1]))
|
||||
{
|
||||
if (blob != NULL)
|
||||
{
|
||||
EMSG(_("E973: Blob literal should have an even number of hex characters"));
|
||||
vim_free(blob);
|
||||
ga_clear(&blob->bv_ga);
|
||||
VIM_CLEAR(blob);
|
||||
}
|
||||
ret = FAIL;
|
||||
break;
|
||||
}
|
||||
@@ -4227,11 +4235,7 @@ eval7(
|
||||
(hex2nr(*bp) << 4) + hex2nr(*(bp+1)));
|
||||
}
|
||||
if (blob != NULL)
|
||||
{
|
||||
++blob->bv_refcount;
|
||||
rettv->v_type = VAR_BLOB;
|
||||
rettv->vval.v_blob = blob;
|
||||
}
|
||||
rettv_blob_set(rettv, blob);
|
||||
*arg = bp;
|
||||
}
|
||||
else
|
||||
|
@@ -795,6 +795,8 @@ static char *(features[]) =
|
||||
|
||||
static int included_patches[] =
|
||||
{ /* Add new patch number below this line */
|
||||
/**/
|
||||
738,
|
||||
/**/
|
||||
737,
|
||||
/**/
|
||||
|
Reference in New Issue
Block a user