krb5 commit: Fix memory leak in SPAKE kdcpreauth module

[email protected]
Newsgroups gmane.comp.encryption.kerberos.cvs
Message-ID <[email protected]>
https://github.com/krb5/krb5/commit/445e1b32767af3041ffd1823996d05ffec6fc9d5
commit 445e1b32767af3041ffd1823996d05ffec6fc9d5
Author: sashan <[email protected]>
Date:   Thu May 26 08:51:10 2022 +0200

    Fix memory leak in SPAKE kdcpreauth module
    
    Commit ff57dc682a27bd205d715f3c0bed84890f2453c4 introduced a memory
    leak into verify_response().  reply_key is no longer passed to the
    callback and therefore needs to be freed by this function.
    
    [[email protected]: rewrote commit message]
    
    ticket: 9061 (new)
    tags: pullup
    target_version: 1.20-next

 src/plugins/preauth/spake/spake_kdc.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/src/plugins/preauth/spake/spake_kdc.c b/src/plugins/preauth/spake/spake_kdc.c
index 687cdc9e0..1a772d450 100644
--- a/src/plugins/preauth/spake/spake_kdc.c
+++ b/src/plugins/preauth/spake/spake_kdc.c
@@ -469,6 +469,7 @@ cleanup:
     zapfree(spakeresult.data, spakeresult.length);
     krb5_free_data_contents(context, &thash);
     krb5_free_keyblock(context, k1);
+    krb5_free_keyblock(context, reply_key);
     k5_free_spake_factor(context, factor);
     (*respond)(arg, ret, NULL, NULL, NULL);
 }
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.