From: Andrej Gessel Date: Tue, 19 Jun 2018 08:07:51 +0000 (+0200) Subject: check return value before using key_values X-Git-Tag: tevent-0.9.37~241 X-Git-Url: http://git.ipfire.org/gitweb.cgi?a=commitdiff_plain;h=f75e8f58cd2390c092631803d333adadb475306a;p=thirdparty%2Fsamba.git check return value before using key_values there are also mem leaks in this function Signed-off-by: Andrej Gessel Reviewed-by: Volker Lendecke Reviewed-by: Jeremy Allison --- diff --git a/lib/ldb/ldb_tdb/ldb_index.c b/lib/ldb/ldb_tdb/ldb_index.c index 9ef786f3a9b..fb606124fb4 100644 --- a/lib/ldb/ldb_tdb/ldb_index.c +++ b/lib/ldb/ldb_tdb/ldb_index.c @@ -1765,13 +1765,14 @@ static int ltdb_index_filter(struct ltdb_private *ltdb, struct guid_tdb_key, dn_list->count); + if (key_values == NULL) { + talloc_free(keys); + return ldb_module_oom(ac->module); + } for (i = 0; i < dn_list->count; i++) { keys[i].dptr = key_values[i].guid_key; keys[i].dsize = sizeof(key_values[i].guid_key); } - if (key_values == NULL) { - return ldb_module_oom(ac->module); - } } else { for (i = 0; i < dn_list->count; i++) { keys[i].dptr = NULL; @@ -1788,6 +1789,7 @@ static int ltdb_index_filter(struct ltdb_private *ltdb, &dn_list->dn[i], &keys[num_keys]); if (ret != LDB_SUCCESS) { + talloc_free(keys); return ret; } @@ -1825,6 +1827,7 @@ static int ltdb_index_filter(struct ltdb_private *ltdb, bool matched; msg = ldb_msg_new(ac); if (!msg) { + talloc_free(keys); return LDB_ERR_OPERATIONS_ERROR; } @@ -1845,6 +1848,7 @@ static int ltdb_index_filter(struct ltdb_private *ltdb, if (ret != LDB_SUCCESS && ret != LDB_ERR_NO_SUCH_OBJECT) { /* an internal error */ + talloc_free(keys); talloc_free(msg); return LDB_ERR_OPERATIONS_ERROR; } @@ -1867,6 +1871,7 @@ static int ltdb_index_filter(struct ltdb_private *ltdb, } if (ret != LDB_SUCCESS) { + talloc_free(keys); talloc_free(msg); return ret; } @@ -1881,6 +1886,7 @@ static int ltdb_index_filter(struct ltdb_private *ltdb, talloc_free(msg); if (ret == -1) { + talloc_free(keys); return LDB_ERR_OPERATIONS_ERROR; } @@ -1890,6 +1896,7 @@ static int ltdb_index_filter(struct ltdb_private *ltdb, * is the callbacks responsiblity, and should * not be talloc_free()'ed */ ac->request_terminated = true; + talloc_free(keys); return ret; }