[PATCH] sunrpc: xdr_bytes/xdr_string need to free buffer on error [BZ #21461]
Florian Weimer
fweimer@redhat.com
Wed Jun 6 08:18:00 GMT 2018
On 05/08/2017 10:39 AM, Andreas Schwab wrote:
> On Mai 08 2017, Florian Weimer <fweimer@redhat.com> wrote:
>
>> +* The xdr_bytes and xdr_string routines free the internally allocated
>> + buffer if deserialization of the buffer contents fails for any reason.
>
> Isn't it the caller's responsibility to call the XDR functions with
> XDR_FREE in any case?
I've decided to follow this interpretation and requested that MITRE
rejects CVE-2017-8804.
Thanks,
Florian
More information about the Libc-alpha
mailing list