0
0
mirror of https://github.com/vim/vim.git synced 2025-09-24 03:44:06 -04:00

patch 8.1.0738: using freed memory, for loop over blob leaks memory

Problem:    Using freed memory, for loop over blob leaks memory.
Solution:   Clear pointer after freeing memory.  Decrement reference count
            after for loop over blob.
This commit is contained in:
Bram Moolenaar
2019-01-13 16:07:21 +01:00
parent e519dfd713
commit ecc8bc482b
2 changed files with 13 additions and 7 deletions

View File

@@ -2615,6 +2615,8 @@ eval_for_line(
clear_tv(&tv);
else
{
// No need to increment the refcount, it's already set for
// the blob being used in "tv".
fi->fi_blob = b;
fi->fi_bi = 0;
}
@@ -2684,6 +2686,8 @@ free_for_info(void *fi_void)
list_rem_watch(fi->fi_list, &fi->fi_lw);
list_unref(fi->fi_list);
}
if (fi != NULL && fi->fi_blob != NULL)
blob_unref(fi->fi_blob);
vim_free(fi);
}
@@ -4217,8 +4221,12 @@ eval7(
{
if (!vim_isxdigit(bp[1]))
{
EMSG(_("E973: Blob literal should have an even number of hex characters"));
vim_free(blob);
if (blob != NULL)
{
EMSG(_("E973: Blob literal should have an even number of hex characters"));
ga_clear(&blob->bv_ga);
VIM_CLEAR(blob);
}
ret = FAIL;
break;
}
@@ -4227,11 +4235,7 @@ eval7(
(hex2nr(*bp) << 4) + hex2nr(*(bp+1)));
}
if (blob != NULL)
{
++blob->bv_refcount;
rettv->v_type = VAR_BLOB;
rettv->vval.v_blob = blob;
}
rettv_blob_set(rettv, blob);
*arg = bp;
}
else

View File

@@ -795,6 +795,8 @@ static char *(features[]) =
static int included_patches[] =
{ /* Add new patch number below this line */
/**/
738,
/**/
737,
/**/