From 559ebc9ccb4752477cc710b6219b24df1a0d13bd Mon Sep 17 00:00:00 2001 From: Jakub Jelen Date: Mon, 6 Mar 2023 12:25:53 +0100 Subject: [PATCH] gssapi: Free mic_token_buffer on before return (GHSL-2023-038) Thanks Phil Turnbull from GitHub Signed-off-by: Jakub Jelen Reviewed-by: Norbert Pocs Reviewed-by: Andreas Schneider --- src/gssapi.c | 3 +++ 1 file changed, 3 insertions(+) diff --git a/src/gssapi.c b/src/gssapi.c index d9644def..7c937168 100644 --- a/src/gssapi.c +++ b/src/gssapi.c @@ -957,6 +957,9 @@ static int ssh_gssapi_send_mic(ssh_session session) SSH2_MSG_USERAUTH_GSSAPI_MIC, mic_token_buf.length, (size_t)mic_token_buf.length, mic_token_buf.value); + + gss_release_buffer(&min_stat, &mic_token_buf); + if (rc != SSH_OK) { SSH_BUFFER_FREE(mic_buffer); ssh_set_error_oom(session);