153aa9179Sopenharmony_ciFrom f0b5515c26a65c218dcab95b411f25f2e57328d0 Mon Sep 17 00:00:00 2001 253aa9179Sopenharmony_ciFrom: Nick Wellnhofer <wellnhofer@aevum.de> 353aa9179Sopenharmony_ciDate: Wed, 2 Nov 2022 15:44:42 +0100 453aa9179Sopenharmony_ciSubject: [PATCH 05/28] malloc-fail: Fix memory leak in xmlStaticCopyNodeList 553aa9179Sopenharmony_ci 653aa9179Sopenharmony_ciFound with libFuzzer, see #344. 753aa9179Sopenharmony_ci 853aa9179Sopenharmony_ciReference: https://github.com/GNOME/libxml2/commit/a22bd982bf10291deea8ba0c61bf75b898c604ce 953aa9179Sopenharmony_ciConflict: NA 1053aa9179Sopenharmony_ci--- 1153aa9179Sopenharmony_ci tree.c | 7 +++++-- 1253aa9179Sopenharmony_ci 1 file changed, 5 insertions(+), 2 deletions(-) 1353aa9179Sopenharmony_ci 1453aa9179Sopenharmony_cidiff --git a/tree.c b/tree.c 1553aa9179Sopenharmony_ciindex 84da156..b32561d 100644 1653aa9179Sopenharmony_ci--- a/tree.c 1753aa9179Sopenharmony_ci+++ b/tree.c 1853aa9179Sopenharmony_ci@@ -4388,7 +4388,7 @@ xmlStaticCopyNodeList(xmlNodePtr node, xmlDocPtr doc, xmlNodePtr parent) { 1953aa9179Sopenharmony_ci } 2053aa9179Sopenharmony_ci if (doc->intSubset == NULL) { 2153aa9179Sopenharmony_ci q = (xmlNodePtr) xmlCopyDtd( (xmlDtdPtr) node ); 2253aa9179Sopenharmony_ci- if (q == NULL) return(NULL); 2353aa9179Sopenharmony_ci+ if (q == NULL) goto error; 2453aa9179Sopenharmony_ci q->doc = doc; 2553aa9179Sopenharmony_ci q->parent = parent; 2653aa9179Sopenharmony_ci doc->intSubset = (xmlDtdPtr) q; 2753aa9179Sopenharmony_ci@@ -4400,7 +4400,7 @@ xmlStaticCopyNodeList(xmlNodePtr node, xmlDocPtr doc, xmlNodePtr parent) { 2853aa9179Sopenharmony_ci } else 2953aa9179Sopenharmony_ci #endif /* LIBXML_TREE_ENABLED */ 3053aa9179Sopenharmony_ci q = xmlStaticCopyNode(node, doc, parent, 1); 3153aa9179Sopenharmony_ci- if (q == NULL) return(NULL); 3253aa9179Sopenharmony_ci+ if (q == NULL) goto error; 3353aa9179Sopenharmony_ci if (ret == NULL) { 3453aa9179Sopenharmony_ci q->prev = NULL; 3553aa9179Sopenharmony_ci ret = p = q; 3653aa9179Sopenharmony_ci@@ -4413,6 +4413,9 @@ xmlStaticCopyNodeList(xmlNodePtr node, xmlDocPtr doc, xmlNodePtr parent) { 3753aa9179Sopenharmony_ci node = node->next; 3853aa9179Sopenharmony_ci } 3953aa9179Sopenharmony_ci return(ret); 4053aa9179Sopenharmony_ci+error: 4153aa9179Sopenharmony_ci+ xmlFreeNodeList(ret); 4253aa9179Sopenharmony_ci+ return(NULL); 4353aa9179Sopenharmony_ci } 4453aa9179Sopenharmony_ci 4553aa9179Sopenharmony_ci /** 4653aa9179Sopenharmony_ci-- 4753aa9179Sopenharmony_ci2.27.0 4853aa9179Sopenharmony_ci 49