Skip to content

Potential NULL dereference of _pool (cl5_clcache.c) #7870

Description

@Ti-Mis

Hi, I was testing this project and came across an interesting point.

Problem:
_pool may be NULL if the cache pool has not been initialized yet. In clcache_get_buffer(), this condition is handled by setting need_new, but execution may still proceed to clcache_enqueue_busy_list() after a new buffer is allocated.

Inside clcache_enqueue_busy_list(), _pool->pl_lock is accessed without checking whether _pool is NULL:

slapi_rwlock_rdlock(_pool->pl_lock) (

slapi_rwlock_rdlock(_pool->pl_lock);
);

This may result in a NULL pointer dereference if clcache_get_buffer() is called before the cache pool is initialized.

Solution:
Add an explicit check that _pool is initialized before calling clcache_enqueue_busy_list(), or otherwise ensure that clcache_get_buffer() cannot be called before clcache_init() has successfully initialized _pool.
389-ds-base v3.1.4
I hope this was helpful!

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    needs triageThe issue will be triaged during scrum

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions