From 282c86597a4929e94e242672379b40dbfc5a49e5 Mon Sep 17 00:00:00 2001 From: noctuum <25441068+noctuum@users.noreply.github.com> Date: Sun, 13 Sep 2026 08:46:51 +0500 Subject: [PATCH] Fix a use after free in the xmlrpc-c index path The string was freed before it was tested, and tmp was never released. --- src/rpc/xmlrpc_c.cc | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/src/rpc/xmlrpc_c.cc b/src/rpc/xmlrpc_c.cc index 08544b03..48b05ad9 100644 --- a/src/rpc/xmlrpc_c.cc +++ b/src/rpc/xmlrpc_c.cc @@ -77,16 +77,18 @@ xmlrpc_list_entry_to_value(xmlrpc_env* env, xmlrpc_value* src, int index) { { const char* str; xmlrpc_read_string(env, tmp, &str); + xmlrpc_DECREF(tmp); if (env->fault_occurred) throw xmlrpc_error_c(env); const char* end = str; int64_t v3 = ::strtoll(str, (char**)&end, 0); + bool invalid = *str == '\0' || *end != '\0'; ::free((void*)str); - if (*str == '\0' || *end != '\0') + if (invalid) throw xmlrpc_error_c(XMLRPC_TYPE_ERROR, "Invalid index."); return v3;