153aa9179Sopenharmony_ciFrom f0b5515c26a65c218dcab95b411f25f2e57328d0 Mon Sep 17 00:00:00 2001
253aa9179Sopenharmony_ciFrom: Nick Wellnhofer <wellnhofer@aevum.de>
353aa9179Sopenharmony_ciDate: Wed, 2 Nov 2022 15:44:42 +0100
453aa9179Sopenharmony_ciSubject: [PATCH 05/28] malloc-fail: Fix memory leak in xmlStaticCopyNodeList
553aa9179Sopenharmony_ci
653aa9179Sopenharmony_ciFound with libFuzzer, see #344.
753aa9179Sopenharmony_ci
853aa9179Sopenharmony_ciReference: https://github.com/GNOME/libxml2/commit/a22bd982bf10291deea8ba0c61bf75b898c604ce
953aa9179Sopenharmony_ciConflict: NA
1053aa9179Sopenharmony_ci---
1153aa9179Sopenharmony_ci tree.c | 7 +++++--
1253aa9179Sopenharmony_ci 1 file changed, 5 insertions(+), 2 deletions(-)
1353aa9179Sopenharmony_ci
1453aa9179Sopenharmony_cidiff --git a/tree.c b/tree.c
1553aa9179Sopenharmony_ciindex 84da156..b32561d 100644
1653aa9179Sopenharmony_ci--- a/tree.c
1753aa9179Sopenharmony_ci+++ b/tree.c
1853aa9179Sopenharmony_ci@@ -4388,7 +4388,7 @@ xmlStaticCopyNodeList(xmlNodePtr node, xmlDocPtr doc, xmlNodePtr parent) {
1953aa9179Sopenharmony_ci 	    }
2053aa9179Sopenharmony_ci 	    if (doc->intSubset == NULL) {
2153aa9179Sopenharmony_ci 		q = (xmlNodePtr) xmlCopyDtd( (xmlDtdPtr) node );
2253aa9179Sopenharmony_ci-		if (q == NULL) return(NULL);
2353aa9179Sopenharmony_ci+		if (q == NULL) goto error;
2453aa9179Sopenharmony_ci 		q->doc = doc;
2553aa9179Sopenharmony_ci 		q->parent = parent;
2653aa9179Sopenharmony_ci 		doc->intSubset = (xmlDtdPtr) q;
2753aa9179Sopenharmony_ci@@ -4400,7 +4400,7 @@ xmlStaticCopyNodeList(xmlNodePtr node, xmlDocPtr doc, xmlNodePtr parent) {
2853aa9179Sopenharmony_ci 	} else
2953aa9179Sopenharmony_ci #endif /* LIBXML_TREE_ENABLED */
3053aa9179Sopenharmony_ci 	    q = xmlStaticCopyNode(node, doc, parent, 1);
3153aa9179Sopenharmony_ci-	if (q == NULL) return(NULL);
3253aa9179Sopenharmony_ci+	if (q == NULL) goto error;
3353aa9179Sopenharmony_ci 	if (ret == NULL) {
3453aa9179Sopenharmony_ci 	    q->prev = NULL;
3553aa9179Sopenharmony_ci 	    ret = p = q;
3653aa9179Sopenharmony_ci@@ -4413,6 +4413,9 @@ xmlStaticCopyNodeList(xmlNodePtr node, xmlDocPtr doc, xmlNodePtr parent) {
3753aa9179Sopenharmony_ci 	node = node->next;
3853aa9179Sopenharmony_ci     }
3953aa9179Sopenharmony_ci     return(ret);
4053aa9179Sopenharmony_ci+error:
4153aa9179Sopenharmony_ci+    xmlFreeNodeList(ret);
4253aa9179Sopenharmony_ci+    return(NULL);
4353aa9179Sopenharmony_ci }
4453aa9179Sopenharmony_ci 
4553aa9179Sopenharmony_ci /**
4653aa9179Sopenharmony_ci-- 
4753aa9179Sopenharmony_ci2.27.0
4853aa9179Sopenharmony_ci
49