Skip to content

Fix: free the filter string leaked by type_build_select - #3153

Merged
greenbonebot merged 1 commit into
mainfrom
fix/84-leak-of-the-filter-string-in-type-build-select
Sep 24, 2026
Merged

greenbonebot merged 1 commit into
mainfrom
fix/84-leak-of-the-filter-string-in-type-build-select

Conversation

@mattmundell

Copy link
Copy Markdown
Contributor

What

Free the filter string that type_build_select obtains from
filter_term (get->filt_id) (or get->filter_replacement) in its cleanup
block, alongside the other allocations it releases.

Why

type_build_select assigned filter and then freed every other allocation in
the block but never that one, so each get_aggregates with a filt_id leaked
a copy of the filter term.

Testing

Before the change, an authenticated get_aggregates with a filter id

<get_aggregates type="nvt" filt_id="..."/>

made gvmd's stderr report a Direct leak of the filter term, allocated by
filter_term and abandoned by type_build_select:

Direct leak of 75 byte(s) in 3 object(s) allocated from:
    #5 sql_string_internal src/sql.c:824
    #6 sql_string src/sql.c:846
    #7 filter_term_sql src/manage_sql_filters.c:2401
    #8 filter_term src/manage_filter_utils.c:844
    #9 type_build_select src/manage_sql.c:28068
    #10 init_aggregate_iterator src/manage_sql.c:1475
    #11 handle_get_aggregates src/gmp.c:12867
SUMMARY: AddressSanitizer: 75 byte(s) leaked in 3 allocation(s).

The request is sent by a user that cannot resolve the filter, so the filter's
name is not fetched on the response path. After the change the same command
completes with no ASan report.

@mattmundell
mattmundell requested review from a team as code owners September 24, 2026 00:08
@greenbonebot
greenbonebot enabled auto-merge (rebase) September 24, 2026 00:08
@bjoernricks
bjoernricks force-pushed the fix/84-leak-of-the-filter-string-in-type-build-select branch from e428414 to 9323a66 Compare September 24, 2026 05:45
@greenbonebot
greenbonebot merged commit bd4677f into main Sep 24, 2026
24 of 25 checks passed
@greenbonebot
greenbonebot deleted the fix/84-leak-of-the-filter-string-in-type-build-select branch September 24, 2026 05:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants