public inbox for [email protected]  
help / color / mirror / Atom feed
From: Tatsuo Ishii <[email protected]>
To: [email protected]
Subject: Re: Memory leak in a SSL module
Date: Mon, 06 Apr 2026 16:20:06 +0900 (JST)
Message-ID: <[email protected]> (raw)
In-Reply-To: <[email protected]>
References: <[email protected]>

> load_dh_file() leaks memory when supplied DH parameters are not valid.
> It should have freed the memory returned by PEM_read_DHparams() using
> DH_free().  The module was first imported from PostgreSQL (commit
> 573bd08b99e277026e87bb55ae69c489fab321b8 2018/1/19) on 2019/6/18 by
> commit 51bc494aaa7fd191e14038204d18effe2efb0ec8.  PostgreSQL found the
> memory leak later on and fixed it by commit
> e835e89a0fd267871e7fbddc39ad00ee3d0cb55c on 2021/3/20.
> 
> While I'm at it, the copyright notice in the same file is fixed. Since
> the code was copied from PostgreSQL, we should retain the original
> PostgreSQL copyright notice.
> 
> Patch attached.

Patch pushed.

Regards,
--
Tatsuo Ishii
SRA OSS K.K.
English: http://www.sraoss.co.jp/index_en/
Japanese:http://www.sraoss.co.jp






reply

Reply instructions:

You may reply publicly to this message via plain-text email
using any one of the following methods:

* Reply to all the recipients using the --to and --cc options:
  reply via email

  To: [email protected]
  Cc: [email protected], [email protected]
  Subject: Re: Memory leak in a SSL module
  In-Reply-To: <[email protected]>

* Save the following mbox file, import it into your mail client,
  and reply-to-all from there: mbox

This inbox is served by agora; see mirroring instructions
for how to clone and mirror all data and code used for this inbox