elf: Fix memory leak in _dl_find_object_update (bug 29062)

The count can be zero if an object has already been loaded as
an indirect dependency (so that l_searchlist.r_list in its link
map is still NULL) is promoted to global scope via RTLD_GLOBAL.

Fixes commit 5d28a8962d ("elf: Add _dl_find_object function").

(cherry picked from commit 4a41fc3cd9)
This commit is contained in:
Florian Weimer 2022-04-13 14:18:28 +02:00
parent db03235895
commit cc9a4a664f
2 changed files with 4 additions and 2 deletions

1
NEWS
View File

@ -21,6 +21,7 @@ The following bugs are resolved with this release:
[28896] strncmp-avx2-rtm and wcsncmp-avx2-rtm fallback on non-rtm
variants when avoiding overflow
[28953] nss: Protect against errno changes in function lookup
[29062] elf: Fix memory leak in _dl_find_object_update
Version 2.35

View File

@ -788,6 +788,9 @@ _dl_find_object_update (struct link_map *new_map)
for (struct link_map *l = new_map; l != NULL; l = l->l_next)
/* Skip proxy maps and already-processed maps. */
count += l == l->l_real && !l->l_find_object_processed;
if (count == 0)
return true;
struct link_map **map_array = malloc (count * sizeof (*map_array));
if (map_array == NULL)
return false;
@ -797,8 +800,6 @@ _dl_find_object_update (struct link_map *new_map)
if (l == l->l_real && !l->l_find_object_processed)
map_array[i++] = l;
}
if (count == 0)
return true;
_dl_find_object_link_map_sort (map_array, count);
bool ok = _dl_find_object_update_1 (map_array, count);