libpq: fix unlikely memory leak

Started by Neil Conwayabout 21 years ago3 messagespatches
Jump to latest
#1Neil Conway
neilc@samurai.com

The attached patch fixes a theoretical memory leak in libpq: if the
second malloc() fails due to OOM, the memory returned by the first
(successful) malloc() will be leaked.

Barring any objections I'll apply this tomorrow.

Per report from EnterpriseDB's Coverity analysis.

-Neil

Attachments:

libpq_send_passwd_mem_leak-1.patchtext/x-patch; name=libpq_send_passwd_mem_leak-1.patchDownload+30-22
#2Tom Lane
tgl@sss.pgh.pa.us
In reply to: Neil Conway (#1)
Re: libpq: fix unlikely memory leak

Neil Conway <neilc@samurai.com> writes:

The attached patch fixes a theoretical memory leak in libpq: if the
second malloc() fails due to OOM, the memory returned by the first
(successful) malloc() will be leaked.

Since both allocations are only transient within this routine, there's
a simpler more effective solution, which is to only do one malloc in
the first place:

char *crypt_pwd2;

/* need enough space for 2 MD5 hashes */
if (!(crypt_pwd = malloc(2 * (MD5_PASSWD_LEN + 1))))
{
fprintf(stderr, libpq_gettext("out of memory\n"));
return STATUS_ERROR;
}
crypt_pwd2 = crypt_pwd + (MD5_PASSWD_LEN + 1);

and drop the free(crypt_pwd2) calls.

regards, tom lane

#3Neil Conway
neilc@samurai.com
In reply to: Tom Lane (#2)
Re: libpq: fix unlikely memory leak

Tom Lane wrote:

Since both allocations are only transient within this routine, there's
a simpler more effective solution, which is to only do one malloc in
the first place

Yeah, true. Attached is a revised patch -- committed to HEAD.

-Neil

Attachments:

libpq_send_passwd_mem_leak-2.patchtext/x-patch; name=libpq_send_passwd_mem_leak-2.patchDownload+7-8