[CDRIVER-208] mongo_cursor_get_more has invalid free of cursor->reply Created: 19/Apr/13 Updated: 09/Aug/13 Resolved: 09/Aug/13 |
|
| Status: | Closed |
| Project: | C Driver |
| Component/s: | None |
| Affects Version/s: | 0.7.1 |
| Fix Version/s: | 0.8.1 |
| Type: | Bug | Priority: | Major - P3 |
| Reporter: | Daniel Brahneborg | Assignee: | Gary Murakami |
| Resolution: | Done | Votes: | 1 |
| Labels: | None | ||
| Remaining Estimate: | Not Specified | ||
| Time Spent: | Not Specified | ||
| Original Estimate: | Not Specified | ||
| Description |
|
The call "bson_free( cursor->reply );" is invalid, since mongo_cursor_destroy() destroys the reply as well, and the reply field is used a few lines down. Patch: diff --git a/src/mongo.c b/src/mongo.c
|
| Comments |
| Comment by Daniel Brahneborg [ 09/Aug/13 ] |
|
It's kind of irrelevant due to /Daniel |
| Comment by auto [ 09/Aug/13 ] |
|
Author: {u'username': u'gjmurakami-10gen', u'name': u'Gary J. Murakami', u'email': u'gary.murakami@10gen.com'}Message: |
| Comment by Gary Murakami [ 09/Aug/13 ] |
|
On further investigation, the line in question is needed to free previously allocated memory. Removing it causes a memory leak which is caught/verified by valgrind. |
| Comment by auto [ 08/Aug/13 ] |
|
Author: {u'username': u'gjmurakami-10gen', u'name': u'Gary J. Murakami', u'email': u'gary.murakami@10gen.com'}Message: mongo_cursor_get_more has invalid free of cursor->reply
|