[31584] in CVS-changelog-for-Kerberos-V5
krb5 commit [krb5-1.22]: Free small client memory leak on OTP failure
daemon@ATHENA.MIT.EDU (ghudson@mit.edu)
Fri Sep 4 20:00:15 2026
From: ghudson@mit.edu
To: cvs-krb5@mit.edu
Message-Id: <20260905000008.288AA105707@krbdev.mit.edu>
Date: Fri, 4 Sep 2026 20:00:08 -0400 (EDT)
MIME-Version: 1.0
Reply-To: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: cvs-krb5-bounces@mit.edu
https://github.com/krb5/krb5/commit/e689b5d54d90a45f4d03ccbdae40fb4037276ea7
commit e689b5d54d90a45f4d03ccbdae40fb4037276ea7
Author: Greg Hudson <ghudson@mit.edu>
Date: Thu Aug 27 19:58:43 2026 -0400
Free small client memory leak on OTP failure
When an initial credentials request using FAST OTP fails due to a
rejection from the KDC, otp_client_prep_questions() may be called
during the processing of the PREAUTH_FAILED response, due to a minor
malfunction in the preauth logic (to be fixed separately). When this
happens the OTP challenge in the PREAUTH_FAILED padata is decoded into
modreq, overwriting and leaking the decoded challenge from the
PREAUTH_REQUIRED response.
Although we don't expect multiple otp_client_prep_questions() calls
when the preauth logic is behaving properly, it could still happen due
to unexpected KDC behavior (such as a MORE_PREAUTH_DATA_REQUIRED
response). Fix the leak in otp_client_prep_questions() so that it
isn't admitted under any KDC behavior.
(cherry picked from commit 82a4224f07ad21c2a3e977c5c4651d7d30c6f1f0)
ticket: 9235
version_fixed: 1.22.3
src/lib/krb5/krb/preauth_otp.c | 12 ++++++++----
1 file changed, 8 insertions(+), 4 deletions(-)
diff --git a/src/lib/krb5/krb/preauth_otp.c b/src/lib/krb5/krb/preauth_otp.c
index 07ffc15c2..abc171f5b 100644
--- a/src/lib/krb5/krb/preauth_otp.c
+++ b/src/lib/krb5/krb/preauth_otp.c
@@ -989,7 +989,7 @@ otp_client_prep_questions(krb5_context context, krb5_clpreauth_moddata moddata,
krb5_data *encoded_previous_request,
krb5_pa_data *pa_data)
{
- krb5_pa_otp_challenge *chl;
+ krb5_pa_otp_challenge *chl, **chp = (krb5_pa_otp_challenge **)modreq;
krb5_error_code retval;
krb5_data tmp;
char *json;
@@ -997,13 +997,17 @@ otp_client_prep_questions(krb5_context context, krb5_clpreauth_moddata moddata,
if (modreq == NULL)
return ENOMEM;
+ /* We shouldn't normally be called twice during the same initial
+ * credentials request, but if we are, free the previous challenge. */
+ k5_free_pa_otp_challenge(context, *chp);
+ *chp = NULL;
+
/* Decode the challenge. */
tmp = make_data(pa_data->contents, pa_data->length);
- retval = decode_krb5_pa_otp_challenge(&tmp,
- (krb5_pa_otp_challenge **)modreq);
+ retval = decode_krb5_pa_otp_challenge(&tmp, chp);
if (retval != 0)
return retval;
- chl = *(krb5_pa_otp_challenge **)modreq;
+ chl = *chp;
/* Remove unsupported tokeninfos. */
retval = filter_supported_tokeninfos(context, chl->tokeninfo);
_______________________________________________
cvs-krb5 mailing list
cvs-krb5@mit.edu
https://mailman.mit.edu/mailman/listinfo/cvs-krb5