From 94a94b09203cc7e8d8959e78c1f46e57c88bb38e Mon Sep 17 00:00:00 2001 From: Matt Mundell Date: Tue, 22 Sep 2026 17:53:38 +0000 Subject: [PATCH] Fix: check the result iterator init in print_report_port_xml print_report_port_xml ignored the return of init_result_get_iterator and then ran next() on the iterator, which is uninitialised when the init fails before touching it (eg the filter referred to by get->filt_id was deleted between the validation and the init). Return when the init fails, leaving a valid empty iterator for the caller to clean up. --- src/manage_sql_report_ports.c | 14 +++++++++++--- 1 file changed, 11 insertions(+), 3 deletions(-) diff --git a/src/manage_sql_report_ports.c b/src/manage_sql_report_ports.c index 3582ad72b..84ecb1d15 100644 --- a/src/manage_sql_report_ports.c +++ b/src/manage_sql_report_ports.c @@ -254,7 +254,7 @@ report_port_count (report_t report) * @param[in] host_filter Exact host filter to apply to the results, * or NULL for no filter. * - * @return 0 on success, -1 error. + * @return 0 on success, 2 if the filter was not found, -1 error. */ int print_report_port_xml (print_report_context_t *ctx, report_t report, FILE *out, @@ -264,9 +264,17 @@ print_report_port_xml (print_report_context_t *ctx, report_t report, FILE *out, const gchar *host_filter) { result_buffer_t *last_item; + int init_ret; ctx->ports = g_array_new (TRUE, FALSE, sizeof (gchar *)); - init_result_get_iterator (results, get, report, host_filter, NULL); + init_ret = init_result_get_iterator (results, get, report, host_filter, NULL); + if (init_ret) + { + /* Leave the iterator valid and empty, so that the callers can clean + * it up even though the init failed before touching it. */ + init_iterator (results, "SELECT NULL WHERE false;"); + return init_ret == 2 ? 2 : -1; + } /* Buffer the results, removing duplicates. */ @@ -426,7 +434,7 @@ print_report_port_xml (print_report_context_t *ctx, report_t report, FILE *out, * @param[in] host_filter Exact host filter to apply to the results, * or NULL for no filter. * - * @return 0 on success, -1 error. + * @return 0 on success, 2 if the filter was not found, -1 error. */ int print_report_port_xml_summary_or_details (print_report_context_t *ctx,