[19218] in Kerberos_V5_Development

home help back first fref pref prev next nref lref last post

Re: memleak in gss_add_cred_with_password in krb 1.12.1 and 1.13.1

daemon@ATHENA.MIT.EDU (Greg Hudson)
Fri Jun 19 17:35:37 2015

Message-ID: <55848B1C.6060101@mit.edu>
Date: Fri, 19 Jun 2015 17:35:24 -0400
From: Greg Hudson <ghudson@mit.edu>
MIME-Version: 1.0
To: Sorin Manolache <sorinm@gmail.com>, krbdev@mit.edu
In-Reply-To: <5582EE34.6070005@gmail.com>
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: krbdev-bounces@mit.edu

On 06/18/2015 12:13 PM, Sorin Manolache wrote:
> I think I've found a memory leak in gss_add_cred_with_password, in krb5 
> 1.12.1 and 1.13.1.
> 
> The gss_OID_set target_mechs in gss_add_cred_with_password 
> (lib/gssapi/mechglue/g_acquire_cred_with_pw.c) is not released if the 
> function returns GSS_S_COMPLETE.

Thanks; I have filed a pull request.  This should be fixed in 1.13.3 and
probably also a 1.12.x patch release.

Be aware that we are planning to change the behavior of
gss_acquire_cred_with_password in 1.14 as discussed here:

    http://krbdev.mit.edu/rt/Ticket/Display.html?id=8152
_______________________________________________
krbdev mailing list             krbdev@mit.edu
https://mailman.mit.edu/mailman/listinfo/krbdev

home help back first fref pref prev next nref lref last post