Closed
Bug 2020486
Opened 7 months ago
Closed 7 months ago
Memory leak in NSC_GenerateKey error path
Categories
(NSS :: Libraries, defect, P3)
NSS
Libraries
Tracking
(nss 3.122, firefox-esr115 wontfix, firefox-esr140 wontfix, firefox148 wontfix, firefox149 wontfix, firefox150 fixed)
People
(Reporter: jschanck, Assigned: jschanck)
Details
(Keywords: sec-low, Whiteboard: [adv-main150+r])
Attachments
(1 file)
In NSC_GenerateKey, the key has a refcount of 2 after the sftk_handleObject here. The sftk_FreeObject call in the cleanup path decrements the refcount to 1, and the caller is responsible for freeing the key with NSC_DestroyObject. However, this is not possible if there is an error in either of the sftk_forceAttribute calls after sftk_handleObject, as the handle is not being returned in that case.
I think errors in sftk_forceAttribute only happen under extreme memory pressure, so this probably does not enable resource exhaustion attacks.
| Assignee | ||
Comment 1•7 months ago
|
||
Pushed by jschanck@mozilla.com:
https://hg.mozilla.org/projects/nss/rev/2dfc9fd5d6d8
fix memory leak in NSC_GenerateKey error path. r=nss-reviewers,rrelyea
Status: ASSIGNED → RESOLVED
Closed: 7 months ago
Resolution: --- → FIXED
Updated•7 months ago
|
Group: crypto-core-security → core-security-release
Updated•6 months ago
|
status-firefox148:
--- → wontfix
status-firefox149:
--- → wontfix
status-firefox150:
--- → fixed
status-firefox-esr115:
--- → wontfix
status-firefox-esr140:
--- → wontfix
Updated•6 months ago
|
QA Whiteboard: [sec] [qa-triage-done-c151/b150]
| Assignee | ||
Updated•5 months ago
|
status-nss:
--- → 3.122
Updated•5 months ago
|
Whiteboard: [adv-main150+r]
Updated•1 month ago
|
Group: core-security-release
You need to log in
before you can comment on or make changes to this bug.
Description
•