|
|
acfc56 |
From b7964157c40066f09411ac52547acb07d1966aee Mon Sep 17 00:00:00 2001
|
|
|
acfc56 |
From: Phil Sutter <psutter@redhat.com>
|
|
|
acfc56 |
Date: Tue, 12 Jan 2021 15:49:43 +0100
|
|
|
acfc56 |
Subject: [PATCH] json: don't leave dangling pointers on hlist
|
|
|
acfc56 |
|
|
|
acfc56 |
Bugzilla: https://bugzilla.redhat.com/show_bug.cgi?id=1900565
|
|
|
acfc56 |
Upstream Status: nftables commit 48917d876d51c
|
|
|
acfc56 |
|
|
|
acfc56 |
commit 48917d876d51cd6ba5bff07172acef05c9e12474
|
|
|
acfc56 |
Author: Florian Westphal <fw@strlen.de>
|
|
|
acfc56 |
Date: Mon Dec 14 16:53:29 2020 +0100
|
|
|
acfc56 |
|
|
|
acfc56 |
json: don't leave dangling pointers on hlist
|
|
|
acfc56 |
|
|
|
acfc56 |
unshare -n tests/json_echo/run-test.py
|
|
|
acfc56 |
[..]
|
|
|
acfc56 |
Adding chain c
|
|
|
acfc56 |
free(): double free detected in tcache 2
|
|
|
acfc56 |
Aborted (core dumped)
|
|
|
acfc56 |
|
|
|
acfc56 |
The element must be deleted from the hlist prior to freeing it.
|
|
|
acfc56 |
|
|
|
acfc56 |
Fixes: 389a0e1edc89a ("json: echo: Speedup seqnum_to_json()")
|
|
|
acfc56 |
Signed-off-by: Florian Westphal <fw@strlen.de>
|
|
|
acfc56 |
---
|
|
|
acfc56 |
src/parser_json.c | 4 +++-
|
|
|
acfc56 |
1 file changed, 3 insertions(+), 1 deletion(-)
|
|
|
acfc56 |
|
|
|
acfc56 |
diff --git a/src/parser_json.c b/src/parser_json.c
|
|
|
acfc56 |
index 785f0e7..986f128 100644
|
|
|
acfc56 |
--- a/src/parser_json.c
|
|
|
acfc56 |
+++ b/src/parser_json.c
|
|
|
acfc56 |
@@ -3670,8 +3670,10 @@ static void json_cmd_assoc_free(void)
|
|
|
acfc56 |
|
|
|
acfc56 |
for (i = 0; i < CMD_ASSOC_HSIZE; i++) {
|
|
|
acfc56 |
hlist_for_each_entry_safe(cur, pos, n,
|
|
|
acfc56 |
- &json_cmd_assoc_hash[i], hnode)
|
|
|
acfc56 |
+ &json_cmd_assoc_hash[i], hnode) {
|
|
|
acfc56 |
+ hlist_del(&cur->hnode);
|
|
|
acfc56 |
free(cur);
|
|
|
acfc56 |
+ }
|
|
|
acfc56 |
}
|
|
|
acfc56 |
}
|
|
|
acfc56 |
|
|
|
acfc56 |
--
|
|
|
8ff5ad |
2.31.1
|
|
|
acfc56 |
|