Closed Bug 2020486 Opened 7 months ago Closed 7 months ago

Memory leak in NSC_GenerateKey error path

Categories

(NSS :: Libraries, defect, P3)

Tracking

(nss 3.122, firefox-esr115 wontfix, firefox-esr140 wontfix, firefox148 wontfix, firefox149 wontfix, firefox150 fixed)

RESOLVED FIXED
Tracking Status
nss --- 3.122
firefox-esr115 --- wontfix
firefox-esr140 --- wontfix
firefox148 --- wontfix
firefox149 --- wontfix
firefox150 --- fixed

People

(Reporter: jschanck, Assigned: jschanck)

Details

(Keywords: sec-low, Whiteboard: [adv-main150+r])

Attachments

(1 file)

48 bytes, text/x-phabricator-request
Details | Review

In NSC_GenerateKey, the key has a refcount of 2 after the sftk_handleObject here. The sftk_FreeObject call in the cleanup path decrements the refcount to 1, and the caller is responsible for freeing the key with NSC_DestroyObject. However, this is not possible if there is an error in either of the sftk_forceAttribute calls after sftk_handleObject, as the handle is not being returned in that case.

I think errors in sftk_forceAttribute only happen under extreme memory pressure, so this probably does not enable resource exhaustion attacks.

Attached file (secure) —

Pushed by jschanck@mozilla.com:
https://hg.mozilla.org/projects/nss/rev/2dfc9fd5d6d8
fix memory leak in NSC_GenerateKey error path. r=nss-reviewers,rrelyea

Status: ASSIGNED → RESOLVED
Closed: 7 months ago
Resolution: --- → FIXED
Group: crypto-core-security → core-security-release
QA Whiteboard: [sec] [qa-triage-done-c151/b150]
status-nss: --- → 3.122
Whiteboard: [adv-main150+r]
Group: core-security-release
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: