From eb62460d914ddf8a7036c7bb22bcd7331b393b8f Mon Sep 17 00:00:00 2001 From: Sam Lantinga Date: Fri, 11 Aug 2017 10:05:45 -0700 Subject: [PATCH] Fixed bug 3723 - Possible double free in kmsdrm init code on certain errors Simon Hug KMSDRM_VideoInit allocates and frees some connectors and encoders but doesn't set the pointer to NULL after freeing. The cleanup code at the end may free one of those garbage pointer should an error happen in the initialization. --- src/video/kmsdrm/SDL_kmsdrmvideo.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/src/video/kmsdrm/SDL_kmsdrmvideo.c b/src/video/kmsdrm/SDL_kmsdrmvideo.c index ac75ec371..e7856ce44 100644 --- a/src/video/kmsdrm/SDL_kmsdrmvideo.c +++ b/src/video/kmsdrm/SDL_kmsdrmvideo.c @@ -325,6 +325,7 @@ KMSDRM_VideoInit(_THIS) } KMSDRM_drmModeFreeConnector(connector); + connector = NULL; } if (i == resources->count_connectors) { @@ -345,6 +346,7 @@ KMSDRM_VideoInit(_THIS) } KMSDRM_drmModeFreeEncoder(encoder); + encoder = NULL; } if (i == resources->count_encoders) {