]> git.ipfire.org Git - thirdparty/haproxy.git/commitdiff
BUG/MEDIUM: quic: fix null deref on error path in qc_conn_init()
authorWilly Tarreau <w@1wt.eu>
Mon, 10 May 2021 05:40:27 +0000 (07:40 +0200)
committerWilly Tarreau <w@1wt.eu>
Mon, 10 May 2021 05:40:27 +0000 (07:40 +0200)
When ctx is NULL, we go to the "err" label, which could dereference it.
No backport is needed.

src/xprt_quic.c

index 68d0f604cbd158abc5353ec2d80456aa06ad1aab..fea9a01586e60e15a8f2227cac612b382cf146ca 100644 (file)
@@ -4164,7 +4164,7 @@ static int qc_conn_init(struct connection *conn, void **xprt_ctx)
        return 0;
 
  err:
-       if (ctx->wait_event.tasklet)
+       if (ctx && ctx->wait_event.tasklet)
                tasklet_free(ctx->wait_event.tasklet);
        pool_free(pool_head_quic_conn_ctx, ctx);
        TRACE_DEVEL("leaving in error", QUIC_EV_CONN_NEW, conn);