36 lines
1.3 KiB
Diff
36 lines
1.3 KiB
Diff
commit 4a41fc3cd9cea9223ea4f13f9c766a1e149a0ccc
|
|
Author: Florian Weimer <fweimer@redhat.com>
|
|
Date: Wed Apr 13 14:18:28 2022 +0200
|
|
|
|
elf: Fix memory leak in _dl_find_object_update (bug 29062)
|
|
|
|
The count can be zero if an object has already been loaded as
|
|
an indirect dependency (so that l_searchlist.r_list in its link
|
|
map is still NULL) is promoted to global scope via RTLD_GLOBAL.
|
|
|
|
Fixes commit 5d28a8962dc ("elf: Add _dl_find_object function").
|
|
|
|
diff --git a/elf/dl-find_object.c b/elf/dl-find_object.c
|
|
index 2952c651ff26db04..f4484e69c226a0a5 100644
|
|
--- a/elf/dl-find_object.c
|
|
+++ b/elf/dl-find_object.c
|
|
@@ -788,6 +788,9 @@ _dl_find_object_update (struct link_map *new_map)
|
|
for (struct link_map *l = new_map; l != NULL; l = l->l_next)
|
|
/* Skip proxy maps and already-processed maps. */
|
|
count += l == l->l_real && !l->l_find_object_processed;
|
|
+ if (count == 0)
|
|
+ return true;
|
|
+
|
|
struct link_map **map_array = malloc (count * sizeof (*map_array));
|
|
if (map_array == NULL)
|
|
return false;
|
|
@@ -797,8 +800,6 @@ _dl_find_object_update (struct link_map *new_map)
|
|
if (l == l->l_real && !l->l_find_object_processed)
|
|
map_array[i++] = l;
|
|
}
|
|
- if (count == 0)
|
|
- return true;
|
|
|
|
_dl_find_object_link_map_sort (map_array, count);
|
|
bool ok = _dl_find_object_update_1 (map_array, count);
|