]> git.ipfire.org Git - thirdparty/openssh-portable.git/commitdiff
upstream commit
authordtucker@openbsd.org <dtucker@openbsd.org>
Fri, 10 Mar 2017 03:22:40 +0000 (03:22 +0000)
committerDarren Tucker <dtucker@zip.com.au>
Fri, 10 Mar 2017 04:25:11 +0000 (15:25 +1100)
Plug descriptor leaks of auth_sock.  From jjelen at
redhat.com via bz#2687, ok djm@

Upstream-ID: 248acb99a5ed2fdca37d1aa33c0fcee7be286d88

sshconnect.c

index 96b91ce1ab4b8a6555de8476f0a70701da125c6f..948b638ad114883a316ca40235626b4bb01009b5 100644 (file)
@@ -1,4 +1,4 @@
-/* $OpenBSD: sshconnect.c,v 1.272 2016/09/12 01:22:38 deraadt Exp $ */
+/* $OpenBSD: sshconnect.c,v 1.273 2017/03/10 03:22:40 dtucker Exp $ */
 /*
  * Author: Tatu Ylonen <ylo@cs.hut.fi>
  * Copyright (c) 1995 Tatu Ylonen <ylo@cs.hut.fi>, Espoo, Finland
@@ -1532,6 +1532,7 @@ maybe_add_key_to_agent(char *authfile, Key *private, char *comment,
        if (options.add_keys_to_agent == 2 &&
            !ask_permission("Add key %s (%s) to agent?", authfile, comment)) {
                debug3("user denied adding this key");
+               close(auth_sock);
                return;
        }
 
@@ -1540,4 +1541,5 @@ maybe_add_key_to_agent(char *authfile, Key *private, char *comment,
                debug("identity added to agent: %s", authfile);
        else
                debug("could not add identity to agent: %s (%d)", authfile, r);
+       close(auth_sock);
 }