NetBSD-Bugs archive

[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index][Old Index]

Re: bin/58887



The following reply was made to PR bin/58887; it has been noted by GNATS.

From: Jose Luis Duran <jlduran%gmail.com@localhost>
To: gnats-bugs%netbsd.org@localhost
Cc: 
Subject: Re: bin/58887
Date: Wed, 17 Dec 2025 12:10:17 -0300

 On Wed, Dec 17, 2025 at 11:30=E2=80=AFAM Christos Zoulas via gnats
 <gnats-admin%netbsd.org@localhost> wrote:
 >
 
 >  The problem is that addchild(..., centry) may free centry and use =3D
 >  samename instead, and then the caller site does: last =3D3D centry; =3D
 >  pointing to free memory. The correct fix I think is to have addchild =3D
 >  return the proper NODE to be assigned as last, instead of leaking memory=
  =3D
 >  and using the old node.
 
 Amazing! Yes, it makes absolute sense. I have tested the patch and it
 indeed avoids the use after free.
 Thank you!
 


Home | Main Index | Thread Index | Old Index