[krbdev.mit.edu #9015] git commit

Greg Hudson via RT rt at krbdev.mit.edu
Mon Jul 12 12:29:30 EDT 2021


<URL: https://krbdev.mit.edu/rt/Ticket/Display.html?id=9015 >


Fix use-after-free during krad remote_shutdown()

Since elements of the queue can be removed on out-of-memory errors,
the correct call is K5_TAILQ_FOREACH_SAFE, not K5_TAILQ_FOREACH.
Reported by Coverity.

(cherry picked from commit 8c88defb16b34937d5b72b4832c854ce2dbe32d1)

https://github.com/krb5/krb5/commit/d8c95fe992fe7e0d9314a28364fc26992f1da628
Author: Robbie Harwood <rharwood at redhat.com>
Committer: Greg Hudson <ghudson at mit.edu>
Commit: d8c95fe992fe7e0d9314a28364fc26992f1da628
Branch: krb5-1.19
 src/lib/krad/remote.c |    4 ++--
 1 files changed, 2 insertions(+), 2 deletions(-)



More information about the krb5-bugs mailing list