Pārlūkot izejas kodu

Fix a use-after-free in validate_intro_point_failure. Bug 17401. Found w valgrind

Nick Mathewson 8 gadi atpakaļ
vecāks
revīzija
5b2070198a
2 mainītis faili ar 5 papildinājumiem un 1 dzēšanām
  1. 3 0
      changes/bug17401
  2. 2 1
      src/or/rendcache.c

+ 3 - 0
changes/bug17401

@@ -0,0 +1,3 @@
+  o Major bugfixes (correctness):
+    - Fix a use-after-free bug in validate_intro_point_failure().
+      Fixes bug 17401; bugfix on 0.2.7.3-rc.

+ 2 - 1
src/or/rendcache.c

@@ -400,9 +400,10 @@ validate_intro_point_failure(const rend_service_descriptor_t *desc,
       /* This intro point is in our cache, discard it from the descriptor
        * because chances are that it's unusable. */
       SMARTLIST_DEL_CURRENT(desc->intro_nodes, intro);
-      rend_intro_point_free(intro);
       /* Keep it for our new entry. */
       digestmap_set(new_entry->intro_failures, (char *) identity, ent_dup);
+      /* Only free it when we're done looking at it. */
+      rend_intro_point_free(intro);
       continue;
     }
   } SMARTLIST_FOREACH_END(intro);