From: Zbigniew Jędrzejewski-Szmek Date: Mon, 9 May 2022 12:28:36 +0000 (+0200) Subject: shared/json: fix memory leak on failed normalization X-Git-Tag: v251-rc3~21^2~5 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=7e4be6a5845f983a299932d4ccb2c4349cf8dd52;p=thirdparty%2Fsystemd.git shared/json: fix memory leak on failed normalization We need to increase the counter immediately after taking the ref, otherwise we may not unref it properly if we fail before incrementing. --- diff --git a/src/shared/json.c b/src/shared/json.c index 55e6d95cdbb..2e52443dde2 100644 --- a/src/shared/json.c +++ b/src/shared/json.c @@ -4655,10 +4655,11 @@ int json_variant_normalize(JsonVariant **v) { if (!a) return -ENOMEM; - for (i = 0; i < m; i++) { + for (i = 0; i < m; ) { a[i] = json_variant_ref(json_variant_by_index(*v, i)); + i++; - r = json_variant_normalize(a + i); + r = json_variant_normalize(&a[i-1]); if (r < 0) goto finish; } diff --git a/test/fuzz/fuzz-json/leak-normalize-fail b/test/fuzz/fuzz-json/leak-normalize-fail new file mode 100644 index 00000000000..b247ccd1991 --- /dev/null +++ b/test/fuzz/fuzz-json/leak-normalize-fail @@ -0,0 +1 @@ +[7E73] \ No newline at end of file