fix: remove use-after-free in transport_ssh.c child process
CI / lint (push) Failing after 3s
CI / build-and-test (push) Has been skipped
CI / sanitizers (address) (push) Has been skipped
CI / clang-tidy (push) Has been skipped
CI / lint (pull_request) Failing after 3s
CI / build-and-test (pull_request) Has been skipped
CI / sanitizers (address) (pull_request) Has been skipped
CI / clang-tidy (pull_request) Has been skipped

remote_dest_destroy(&r) was called before r.user and r.host
were accessed to build the SSH username string. Since the child
process _exit()s, memory cleanup is unnecessary there.
This commit is contained in:
2026-07-20 17:14:57 +02:00
parent 38be7c090a
commit 0d7cb7230d
-3
View File
@@ -111,9 +111,6 @@ Client* client_connect_ssh(const char* destination, int port) {
close(sv[0]); close(sv[0]);
close(exec_pipe[0]); close(exec_pipe[0]);
fcntl(exec_pipe[1], F_SETFD, FD_CLOEXEC); fcntl(exec_pipe[1], F_SETFD, FD_CLOEXEC);
// Child doesn't need the RemoteDest strings
remote_dest_destroy(&r);
if (sv[1] != STDIN_FILENO) if (sv[1] != STDIN_FILENO)
dup2(sv[1], STDIN_FILENO); dup2(sv[1], STDIN_FILENO);
if (sv[1] != STDOUT_FILENO) if (sv[1] != STDOUT_FILENO)