]> git.ipfire.org Git - thirdparty/shadow.git/commitdiff
fix: memory leak of nsgrp in src/useradd.c grp_update() master
authorArtem Semenov <savoptik@altlinux.org>
Mon, 8 Jun 2026 12:34:35 +0000 (15:34 +0300)
committerAlejandro Colomar <foss+github@alejandro-colomar.es>
Thu, 6 Aug 2026 13:53:48 +0000 (15:53 +0200)
grp_update() also duplicates each shadow group with __sgr_dup() and
never frees the 'nsgrp' copy.  Release it with sgr_free().

valgrind --leak-check=full --show-leak-kinds=all \
    src/useradd -M -N -G grp1,...,grp10 alice, before this commit:

    691 (320 direct, 371 indirect) bytes in 10 blocks are definitely lost
       at 0x4848EB8: calloc
       by __sgr_dup (sgroupio.c:37)
       by grp_update (useradd.c:1104)
    definitely lost: 480 bytes in 30 blocks

after this commit:

    definitely lost: 160 bytes in 20 blocks

Signed-off-by: Artem Semenov <savoptik@altlinux.org>
Reviewed-by: Alejandro Colomar <alx@kernel.org>
src/useradd.c

index e243c68570607622ab5903415bc4451c793f8351..25b7f4f3c9b0413251c4256d8e3bbcd050ecfae0 100644 (file)
@@ -1125,6 +1125,7 @@ static void grp_update (bool process_selinux)
 #endif
                SYSLOG(LOG_INFO, "add '%s' to shadow group '%s'",
                       user_name, nsgrp->sg_namp);
 #endif
                SYSLOG(LOG_INFO, "add '%s' to shadow group '%s'",
                       user_name, nsgrp->sg_namp);
+               sgr_free (nsgrp);
        }
 #endif                         /* SHADOWGRP */
 }
        }
 #endif                         /* SHADOWGRP */
 }