wayland: fix use-after-free in popup resource destroy callback
ASAN found the heap corruption bug. When a toplevel is destroyed, the view is freed but the wmaker-popup-v1 wl_resource still exists. When the client later disconnects, wayland-server calls the resource destroy callback which accessed the freed view (writing to view->popup). This corrupted whatever was subsequently allocated in that memory region, causing the SIGSEGV-in-malloc crashes. Fix: NULL out the resource user_data before freeing the view.
This commit is contained in:
parent
46f0defabd
commit
09d3895642
|
|
@ -454,6 +454,10 @@ handle_toplevel_destroy(struct wl_listener *listener, void *data)
|
|||
wfree(view->wm_command[ci]);
|
||||
wfree(view->wm_command);
|
||||
}
|
||||
/* Clear popup resource user_data so the resource destroy callback
|
||||
* doesn't access the freed view. */
|
||||
if (view->popup)
|
||||
wl_resource_set_user_data(view->popup, NULL);
|
||||
/* Save frame_id before freeing view */
|
||||
WNativeWindow frame_id = view->frame_id;
|
||||
wfree(view);
|
||||
|
|
|
|||
Loading…
Reference in New Issue