OpenAFS Master Repository branch, master, updated. openafs-devel-1_9_1-267-g915c9ec

Gerrit Code Review gerrit@openafs.org
Thu, 18 May 2023 12:17:10 -0400


The following commit has been merged in the master branch:
commit 915c9ec007810f99a5ea8be73426fc8882f615fd
Author: Mark Vitale <mvitale@sinenomine.net>
Date:   Fri May 12 21:25:36 2023 -0400

    rxkad: Free memory used to check rxkad response
    
    Since its introduction with commit 7e4e06b87a09 "Derive DES/fcrypt
    session key from other key types", rxkad_derive_des_key has failed to
    free the memory associated with its HMAC context struct.
    
    This results in a leak of at least 352 bytes for each rxkad challenge
    response processed by an OpenAFS server when using rxkad-kdf.
    
    Free the memory by calling HMAC_CTX_cleanup after each round of the
    loop.
    
    Discovered via Solaris libumem.so.1.
    
    Change-Id: Ic9f130f7229c70e4eaa68ba1f0a213b4b23229cc
    Reviewed-on: https://gerrit.openafs.org/15427
    Tested-by: BuildBot <buildbot@rampaginggeek.com>
    Reviewed-by: Andrew Deason <adeason@sinenomine.net>
    Reviewed-by: Cheyenne Wills <cwills@sinenomine.net>
    Reviewed-by: Benjamin Kaduk <kaduk@mit.edu>

 src/rxkad/ticket5.c | 1 +
 1 file changed, 1 insertion(+)

-- 
OpenAFS Master Repository