From: Stefan Eissing Date: Wed, 6 Mar 2024 08:36:08 +0000 (+0100) Subject: [PATCH] http2: push headers better cleanup X-Git-Tag: archive/raspbian/7.88.1-10+rpi1+deb12u6^2~3 X-Git-Url: https://dgit.raspbian.org/?a=commitdiff_plain;h=7c606dd1e3462b2ec971f39ea234ca1477239233;p=curl.git [PATCH] http2: push headers better cleanup - provide common cleanup method for push headers Closes #13054 Backported by: Guilherme Puida Moreira : * Changed h2_stream_ctx to HTTP in free_push_headers. Gbp-Pq: Name CVE-2024-2398.patch --- diff --git a/lib/http2.c b/lib/http2.c index bdb5e737..76677882 100644 --- a/lib/http2.c +++ b/lib/http2.c @@ -229,6 +229,15 @@ static CURLcode http2_data_setup(struct Curl_cfilter *cf, return CURLE_OK; } +static void free_push_headers(struct HTTP *stream) +{ + size_t i; + for(i = 0; ipush_headers_used; i++) + free(stream->push_headers[i]); + Curl_safefree(stream->push_headers); + stream->push_headers_used = 0; +} + /* * Initialize the cfilter context */ @@ -702,7 +711,6 @@ static int push_promise(struct Curl_cfilter *cf, struct HTTP *newstream; struct curl_pushheaders heads; CURLMcode rc; - size_t i; /* clone the parent */ struct Curl_easy *newhandle = h2_duphandle(cf, data); if(!newhandle) { @@ -738,11 +746,7 @@ static int push_promise(struct Curl_cfilter *cf, Curl_set_in_callback(data, false); /* free the headers again */ - for(i = 0; ipush_headers_used; i++) - free(stream->push_headers[i]); - free(stream->push_headers); - stream->push_headers = NULL; - stream->push_headers_used = 0; + free_push_headers(stream); if(rv) { DEBUGASSERT((rv > CURL_PUSH_OK) && (rv <= CURL_PUSH_ERROROUT)); @@ -1198,14 +1202,14 @@ static int on_header(nghttp2_session *session, const nghttp2_frame *frame, if(stream->push_headers_alloc > 1000) { /* this is beyond crazy many headers, bail out */ failf(data_s, "Too many PUSH_PROMISE headers"); - Curl_safefree(stream->push_headers); + free_push_headers(stream); return NGHTTP2_ERR_TEMPORAL_CALLBACK_FAILURE; } stream->push_headers_alloc *= 2; - headp = Curl_saferealloc(stream->push_headers, - stream->push_headers_alloc * sizeof(char *)); + headp = realloc(stream->push_headers, + stream->push_headers_alloc * sizeof(char *)); if(!headp) { - stream->push_headers = NULL; + free_push_headers(stream); return NGHTTP2_ERR_TEMPORAL_CALLBACK_FAILURE; } stream->push_headers = headp; @@ -1364,14 +1368,7 @@ static void http2_data_done(struct Curl_cfilter *cf, setup */ Curl_dyn_free(&stream->header_recvbuf); Curl_dyn_free(&stream->trailer_recvbuf); - if(stream->push_headers) { - /* if they weren't used and then freed before */ - for(; stream->push_headers_used > 0; --stream->push_headers_used) { - free(stream->push_headers[stream->push_headers_used - 1]); - } - free(stream->push_headers); - stream->push_headers = NULL; - } + free_push_headers(stream); if(!ctx || !ctx->h2) return;