[31584] in CVS-changelog-for-Kerberos-V5

home help back first fref pref prev next nref lref last post

krb5 commit [krb5-1.22]: Free small client memory leak on OTP failure

daemon@ATHENA.MIT.EDU (ghudson@mit.edu)
Fri Sep 4 20:00:15 2026

From: ghudson@mit.edu
To: cvs-krb5@mit.edu
Message-Id: <20260905000008.288AA105707@krbdev.mit.edu>
Date: Fri,  4 Sep 2026 20:00:08 -0400 (EDT)
MIME-Version: 1.0
Reply-To: krbdev@mit.edu
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: 7bit
Errors-To: cvs-krb5-bounces@mit.edu

https://github.com/krb5/krb5/commit/e689b5d54d90a45f4d03ccbdae40fb4037276ea7
commit e689b5d54d90a45f4d03ccbdae40fb4037276ea7
Author: Greg Hudson <ghudson@mit.edu>
Date:   Thu Aug 27 19:58:43 2026 -0400

    Free small client memory leak on OTP failure
    
    When an initial credentials request using FAST OTP fails due to a
    rejection from the KDC, otp_client_prep_questions() may be called
    during the processing of the PREAUTH_FAILED response, due to a minor
    malfunction in the preauth logic (to be fixed separately).  When this
    happens the OTP challenge in the PREAUTH_FAILED padata is decoded into
    modreq, overwriting and leaking the decoded challenge from the
    PREAUTH_REQUIRED response.
    
    Although we don't expect multiple otp_client_prep_questions() calls
    when the preauth logic is behaving properly, it could still happen due
    to unexpected KDC behavior (such as a MORE_PREAUTH_DATA_REQUIRED
    response).  Fix the leak in otp_client_prep_questions() so that it
    isn't admitted under any KDC behavior.
    
    (cherry picked from commit 82a4224f07ad21c2a3e977c5c4651d7d30c6f1f0)
    
    ticket: 9235
    version_fixed: 1.22.3

 src/lib/krb5/krb/preauth_otp.c | 12 ++++++++----
 1 file changed, 8 insertions(+), 4 deletions(-)

diff --git a/src/lib/krb5/krb/preauth_otp.c b/src/lib/krb5/krb/preauth_otp.c
index 07ffc15c2..abc171f5b 100644
--- a/src/lib/krb5/krb/preauth_otp.c
+++ b/src/lib/krb5/krb/preauth_otp.c
@@ -989,7 +989,7 @@ otp_client_prep_questions(krb5_context context, krb5_clpreauth_moddata moddata,
                           krb5_data *encoded_previous_request,
                           krb5_pa_data *pa_data)
 {
-    krb5_pa_otp_challenge *chl;
+    krb5_pa_otp_challenge *chl, **chp = (krb5_pa_otp_challenge **)modreq;
     krb5_error_code retval;
     krb5_data tmp;
     char *json;
@@ -997,13 +997,17 @@ otp_client_prep_questions(krb5_context context, krb5_clpreauth_moddata moddata,
     if (modreq == NULL)
         return ENOMEM;
 
+    /* We shouldn't normally be called twice during the same initial
+     * credentials request, but if we are, free the previous challenge. */
+    k5_free_pa_otp_challenge(context, *chp);
+    *chp = NULL;
+
     /* Decode the challenge. */
     tmp = make_data(pa_data->contents, pa_data->length);
-    retval = decode_krb5_pa_otp_challenge(&tmp,
-                                          (krb5_pa_otp_challenge **)modreq);
+    retval = decode_krb5_pa_otp_challenge(&tmp, chp);
     if (retval != 0)
         return retval;
-    chl = *(krb5_pa_otp_challenge **)modreq;
+    chl = *chp;
 
     /* Remove unsupported tokeninfos. */
     retval = filter_supported_tokeninfos(context, chl->tokeninfo);
_______________________________________________
cvs-krb5 mailing list
cvs-krb5@mit.edu
https://mailman.mit.edu/mailman/listinfo/cvs-krb5

home help back first fref pref prev next nref lref last post