Uploaded image for project: 'RHEL'
  1. RHEL
  2. RHEL-29317

Memory leak in 'pamsrv_gssapi.c'

Linking RHIVOS CVEs to...Migration: Automation ...SWIFT: POC ConversionSync from "Extern...XMLWordPrintable

    • Icon: Bug Bug
    • Resolution: Done
    • Icon: Minor Minor
    • None
    • rhel-9.3.0
    • sssd
    • None
    • Low
    • rhel-idm-sssd
    • ssg_idm
    • 2
    • False
    • False
    • Hide

      None

      Show
      None
    • None
    • None
    • None

      Error: RESOURCE_LEAK (CWE-772):
      sssd-2.9.1/src/responder/pam/pamsrv_gssapi.c:750: alloc_arg: ""gss_accept_sec_context"" allocates memory that is stored into ""client_name"".
      sssd-2.9.1/src/responder/pam/pamsrv_gssapi.c:806: leaked_storage: Variable ""client_name"" going out of scope leaks the storage it points to.
      #  804|       gss_release_buffer(&minor, &output);
      #  805|   
      #  806|->     return ret;
      #  807|   }
      #  808|   
      

              atikhono@redhat.com Alexey Tikhonov
              atikhono@redhat.com Alexey Tikhonov
              SSSD Maintainers SSSD Maintainers
              Jakub Vavra Jakub Vavra
              Louise McGarry Louise McGarry
              Votes:
              0 Vote for this issue
              Watchers:
              13 Start watching this issue

                Created:
                Updated:
                Resolved: