[xerces-c] branch master updated: DFAContentModel::buildSyntaxTree(): fix memory leaks when OutOfMemoryException occurs

[email protected]
Newsgroups gmane.text.xml.xerces-c.devel
Message-ID <[email protected]>
This is an automated email from the ASF dual-hosted git repository.

rleigh pushed a commit to branch master
in repository https://gitbox.apache.org/repos/asf/xerces-c.git


The following commit(s) were added to refs/heads/master by this push:
     new cb4b4cf  DFAContentModel::buildSyntaxTree(): fix memory leaks when OutOfMemoryException occurs
     new 8ac9637  Merge pull request #43 from rouault/dfa_buildsyntax_tree_memleak
cb4b4cf is described below

commit cb4b4cf70a2a69fdf18bd6c06924e923b9b21aab
Author: Even Rouault <[email protected]>
AuthorDate: Mon Nov 15 17:32:26 2021 +0100

    DFAContentModel::buildSyntaxTree(): fix memory leaks when OutOfMemoryException occurs
    
    Fixes GDAL's https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=40866
---
 src/xercesc/validators/common/DFAContentModel.cpp | 60 ++++++++++++++---------
 1 file changed, 36 insertions(+), 24 deletions(-)

diff --git a/src/xercesc/validators/common/DFAContentModel.cpp b/src/xercesc/validators/common/DFAContentModel.cpp
index ddca8ec..6d6b124 100644
--- a/src/xercesc/validators/common/DFAContentModel.cpp
+++ b/src/xercesc/validators/common/DFAContentModel.cpp
@@ -1498,33 +1498,45 @@ CMNode* DFAContentModel::buildSyntaxTree(ContentSpecNode* const curNode
             retNode = buildSyntaxTree(cursor, curIndex);
             for(unsigned int i=0;i<nLoopCount;i++)
             {
-                CMNode* newRight = buildSyntaxTree(rightNode, curIndex);
-                //
-                //  Now handle our level. We use our left child's last pos set and our
-                //  right child's first pos set, so get them now for convenience.
-                //
-                const CMStateSet& last  = retNode->getLastPos();
-                const CMStateSet& first = newRight->getFirstPos();
+                CMNode* newRight = nullptr;
+                try
+                {
+                    newRight = buildSyntaxTree(rightNode, curIndex);
 
-                //
-                //  Now, for every position which is in our left child's last set
-                //  add all of the states in our right child's first set to the
-                //  follow set for that position.
-                //
-                CMStateSetEnumerator enumLast(&last);
-                while(enumLast.hasMoreElements())
+                    //
+                    //  Now handle our level. We use our left child's last pos set and our
+                    //  right child's first pos set, so get them now for convenience.
+                    //
+                    const CMStateSet& last  = retNode->getLastPos();
+                    const CMStateSet& first = newRight->getFirstPos();
+
+                    //
+                    //  Now, for every position which is in our left child's last set
+                    //  add all of the states in our right child's first set to the
+                    //  follow set for that position.
+                    //
+                    CMStateSetEnumerator enumLast(&last);
+                    while(enumLast.hasMoreElements())
+                    {
+                        XMLSize_t index=enumLast.nextElement();
+                        *fFollowList[index] |= first;
+                    }
+
+                    retNode = new (fMemoryManager) CMBinaryOp
+                    (
+                        ContentSpecNode::Sequence
+                        , retNode
+                        , newRight
+                        , fLeafCount
+                        , fMemoryManager
+                    );
+                }
+                catch( const OutOfMemoryException& )
                 {
-                    XMLSize_t index=enumLast.nextElement();
-                    *fFollowList[index] |= first;
+                    delete newRight;
+                    delete retNode;
+                    throw;
                 }
-                retNode = new (fMemoryManager) CMBinaryOp
-                (
-                    ContentSpecNode::Sequence
-                    , retNode
-                    , newRight
-                    , fLeafCount
-                    , fMemoryManager
-                );
             }
             return retNode;
         }
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.