public inbox for binutils@sourceware.org
 help / color / mirror / Atom feed
* [PATCH 1/1] libctf: Fix double free in ctf_link_add_cu_mapping.
@ 2022-12-07 14:11 Felix Willgerodt
  2022-12-08  1:22 ` Alan Modra
  0 siblings, 1 reply; 4+ messages in thread
From: Felix Willgerodt @ 2022-12-07 14:11 UTC (permalink / raw)
  To: binutils; +Cc: Felix Willgerodt

This fixes a potential double free which can occur if we jump to
oom_noerrno after the first free.

I am not very familiar with libctf, so any comments are welcome.
I am wondering if the right solution wouldn't be to free both t and f before
the "return 0".  But I didn't fully understand the code and saw that other
users of ctf_dynhash_insert() also don't free the key manually.

libctf/ChangeLog:
* ctf-link.c (ctf_link_add_cu_mapping): Adjust freeing logic.
---
 libctf/ctf-link.c | 2 --
 1 file changed, 2 deletions(-)

diff --git a/libctf/ctf-link.c b/libctf/ctf-link.c
index 702f2b4d5fe..e59e415eb41 100644
--- a/libctf/ctf-link.c
+++ b/libctf/ctf-link.c
@@ -430,8 +430,6 @@ ctf_link_add_cu_mapping (ctf_dict_t *fp, const char *from, const char *to)
 	  goto oom_noerrno;
 	}
     }
-  else
-    free (t);
 
   if (ctf_dynhash_insert (one_out, f, NULL) < 0)
     {
-- 
2.34.3

Intel Deutschland GmbH
Registered Address: Am Campeon 10, 85579 Neubiberg, Germany
Tel: +49 89 99 8853-0, www.intel.de <http://www.intel.de>
Managing Directors: Christin Eisenschmid, Sharon Heck, Tiffany Doon Silva  
Chairperson of the Supervisory Board: Nicole Lau
Registered Office: Munich
Commercial Register: Amtsgericht Muenchen HRB 186928


^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH 1/1] libctf: Fix double free in ctf_link_add_cu_mapping.
  2022-12-07 14:11 [PATCH 1/1] libctf: Fix double free in ctf_link_add_cu_mapping Felix Willgerodt
@ 2022-12-08  1:22 ` Alan Modra
  2022-12-08  7:47   ` Willgerodt, Felix
  2022-12-15 15:26   ` Nick Alcock
  0 siblings, 2 replies; 4+ messages in thread
From: Alan Modra @ 2022-12-08  1:22 UTC (permalink / raw)
  To: Felix Willgerodt; +Cc: binutils

On Wed, Dec 07, 2022 at 03:11:37PM +0100, Felix Willgerodt via Binutils wrote:
> This fixes a potential double free which can occur if we jump to
> oom_noerrno after the first free.
> 
> I am not very familiar with libctf, so any comments are welcome.
> I am wondering if the right solution wouldn't be to free both t and f before
> the "return 0".  But I didn't fully understand the code and saw that other
> users of ctf_dynhash_insert() also don't free the key manually.

No, they can't be freed if successfully inserted into the hash table,
but "t" should indeed be freed if already inserted.  I'm applying the
following fix.

	* ctf-link.c (ctf_link_add_cu_mapping): Set t NULL after free.

diff --git a/libctf/ctf-link.c b/libctf/ctf-link.c
index 702f2b4d5fe..902b4408cd6 100644
--- a/libctf/ctf-link.c
+++ b/libctf/ctf-link.c
@@ -431,7 +431,10 @@ ctf_link_add_cu_mapping (ctf_dict_t *fp, const char *from, const char *to)
 	}
     }
   else
-    free (t);
+    {
+      free (t);
+      t = NULL;
+    }
 
   if (ctf_dynhash_insert (one_out, f, NULL) < 0)
     {


-- 
Alan Modra
Australia Development Lab, IBM

^ permalink raw reply	[flat|nested] 4+ messages in thread

* RE: [PATCH 1/1] libctf: Fix double free in ctf_link_add_cu_mapping.
  2022-12-08  1:22 ` Alan Modra
@ 2022-12-08  7:47   ` Willgerodt, Felix
  2022-12-15 15:26   ` Nick Alcock
  1 sibling, 0 replies; 4+ messages in thread
From: Willgerodt, Felix @ 2022-12-08  7:47 UTC (permalink / raw)
  To: Alan Modra; +Cc: binutils

> -----Original Message-----
> From: Alan Modra <amodra@gmail.com>
> Sent: Donnerstag, 8. Dezember 2022 02:23
> To: Willgerodt, Felix <felix.willgerodt@intel.com>
> Cc: binutils@sourceware.org
> Subject: Re: [PATCH 1/1] libctf: Fix double free in ctf_link_add_cu_mapping.
> 
> On Wed, Dec 07, 2022 at 03:11:37PM +0100, Felix Willgerodt via Binutils
> wrote:
> > This fixes a potential double free which can occur if we jump to
> > oom_noerrno after the first free.
> >
> > I am not very familiar with libctf, so any comments are welcome.
> > I am wondering if the right solution wouldn't be to free both t and f before
> > the "return 0".  But I didn't fully understand the code and saw that other
> > users of ctf_dynhash_insert() also don't free the key manually.
> 
> No, they can't be freed if successfully inserted into the hash table,
> but "t" should indeed be freed if already inserted.  I'm applying the
> following fix.
> 
> 	* ctf-link.c (ctf_link_add_cu_mapping): Set t NULL after free.
> 
> diff --git a/libctf/ctf-link.c b/libctf/ctf-link.c
> index 702f2b4d5fe..902b4408cd6 100644
> --- a/libctf/ctf-link.c
> +++ b/libctf/ctf-link.c
> @@ -431,7 +431,10 @@ ctf_link_add_cu_mapping (ctf_dict_t *fp, const char
> *from, const char *to)
>  	}
>      }
>    else
> -    free (t);
> +    {
> +      free (t);
> +      t = NULL;
> +    }
> 
>    if (ctf_dynhash_insert (one_out, f, NULL) < 0)
>      {
> 
> 
> --
> Alan Modra
> Australia Development Lab, IBM

Thanks, that looks fine to me as well.

Felix
Intel Deutschland GmbH
Registered Address: Am Campeon 10, 85579 Neubiberg, Germany
Tel: +49 89 99 8853-0, www.intel.de <http://www.intel.de>
Managing Directors: Christin Eisenschmid, Sharon Heck, Tiffany Doon Silva  
Chairperson of the Supervisory Board: Nicole Lau
Registered Office: Munich
Commercial Register: Amtsgericht Muenchen HRB 186928

^ permalink raw reply	[flat|nested] 4+ messages in thread

* Re: [PATCH 1/1] libctf: Fix double free in ctf_link_add_cu_mapping.
  2022-12-08  1:22 ` Alan Modra
  2022-12-08  7:47   ` Willgerodt, Felix
@ 2022-12-15 15:26   ` Nick Alcock
  1 sibling, 0 replies; 4+ messages in thread
From: Nick Alcock @ 2022-12-15 15:26 UTC (permalink / raw)
  To: Felix Willgerodt, Alan Modra; +Cc: binutils

On 8 Dec 2022, Alan Modra via Binutils stated:

> On Wed, Dec 07, 2022 at 03:11:37PM +0100, Felix Willgerodt via Binutils wrote:
>> This fixes a potential double free which can occur if we jump to
>> oom_noerrno after the first free.
>> 
>> I am not very familiar with libctf, so any comments are welcome.
>> I am wondering if the right solution wouldn't be to free both t and f before
>> the "return 0".  But I didn't fully understand the code and saw that other
>> users of ctf_dynhash_insert() also don't free the key manually.
>
> No, they can't be freed if successfully inserted into the hash table,
> but "t" should indeed be freed if already inserted.  I'm applying the
> following fix.
>
> 	* ctf-link.c (ctf_link_add_cu_mapping): Set t NULL after free.
>
> diff --git a/libctf/ctf-link.c b/libctf/ctf-link.c
> index 702f2b4d5fe..902b4408cd6 100644
> --- a/libctf/ctf-link.c
> +++ b/libctf/ctf-link.c
> @@ -431,7 +431,10 @@ ctf_link_add_cu_mapping (ctf_dict_t *fp, const char *from, const char *to)
>  	}
>      }
>    else
> -    free (t);
> +    {
> +      free (t);
> +      t = NULL;
> +    }
>  
>    if (ctf_dynhash_insert (one_out, f, NULL) < 0)
>      {

Looks good! Sorry about that. This function has been subject to more
OOM-related memory allocation problems than everything else in libctf
combined :/

-- 
NULL && (void)

^ permalink raw reply	[flat|nested] 4+ messages in thread

end of thread, other threads:[~2022-12-15 15:27 UTC | newest]

Thread overview: 4+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2022-12-07 14:11 [PATCH 1/1] libctf: Fix double free in ctf_link_add_cu_mapping Felix Willgerodt
2022-12-08  1:22 ` Alan Modra
2022-12-08  7:47   ` Willgerodt, Felix
2022-12-15 15:26   ` Nick Alcock

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for read-only IMAP folder(s) and NNTP newsgroup(s).