summaryrefslogtreecommitdiffstats
diff options
context:
space:
mode:
authorJeremy Allison <jra@samba.org>2008-02-29 06:55:48 -0800
committerJeremy Allison <jra@samba.org>2008-02-29 06:55:48 -0800
commitb214365ec32c1904ea763cccd0b2b49f5f6f0869 (patch)
tree304da284c57f3dc211e83a57f26eee54f78bce7d
parent20971d829d7ae2c1b31ebc872da787f3467fa6b0 (diff)
downloadsamba-b214365ec32c1904ea763cccd0b2b49f5f6f0869.tar.gz
samba-b214365ec32c1904ea763cccd0b2b49f5f6f0869.tar.xz
samba-b214365ec32c1904ea763cccd0b2b49f5f6f0869.zip
Patch to fix the "Invalid read of size 4" errors. Bug #3617.
Jeremy.
-rw-r--r--source/nmbd/nmbd_responserecordsdb.c18
1 files changed, 18 insertions, 0 deletions
diff --git a/source/nmbd/nmbd_responserecordsdb.c b/source/nmbd/nmbd_responserecordsdb.c
index 8b056acbcde..dc16a07ccfc 100644
--- a/source/nmbd/nmbd_responserecordsdb.c
+++ b/source/nmbd/nmbd_responserecordsdb.c
@@ -47,6 +47,24 @@ static void add_response_record(struct subnet_record *subrec,
void remove_response_record(struct subnet_record *subrec,
struct response_record *rrec)
{
+ /* It is possible this can be called twice,
+ with a rrec pointer that has been freed. So
+ before we inderect into rrec, search for it
+ on the responselist first. Bug #3617. JRA. */
+
+ struct response_record *p = NULL;
+
+ for (p = subrec->responselist; p; p = p->next) {
+ if (p == rrec) {
+ break;
+ }
+ }
+
+ if (p == NULL) {
+ /* We didn't find rrec on the list. */
+ return;
+ }
+
DLIST_REMOVE(subrec->responselist, rrec);
if(rrec->userdata) {