[krbdev.mit.edu #9015] git commit

Greg Hudson via RT rt at krbdev.mit.edu
Mon Jul 12 12:41:52 EDT 2021


<URL: https://krbdev.mit.edu/rt/Ticket/Display.html?id=9015 >


Fix use-after-free during krad remote_shutdown()

Since elements of the queue can be removed on out-of-memory errors,
the correct call is K5_TAILQ_FOREACH_SAFE, not K5_TAILQ_FOREACH.
Reported by Coverity.

(cherry picked from commit 8c88defb16b34937d5b72b4832c854ce2dbe32d1)

https://github.com/krb5/krb5/commit/ed1ee79e90ccf485eed370dbda83829046502139
Author: Robbie Harwood <rharwood at redhat.com>
Committer: Greg Hudson <ghudson at mit.edu>
Commit: ed1ee79e90ccf485eed370dbda83829046502139
Branch: krb5-1.18
 src/lib/krad/remote.c |    4 ++--
 1 files changed, 2 insertions(+), 2 deletions(-)



More information about the krb5-bugs mailing list