diff --git a/CHANGES b/CHANGES index 1eadd10ef2..70e4570cb0 100644 --- a/CHANGES +++ b/CHANGES @@ -1,3 +1,6 @@ +5286. [contrib] Address potential NULL pointer dereferences in + dlz_mysqldyn_mod.c. [GL #1207] + 5285. [port] win32: implement "-T maxudpXXX". [GL #837] 5282. [bug] Fixed a bug in searching for possible wildcard matches diff --git a/contrib/dlz/modules/mysqldyn/dlz_mysqldyn_mod.c b/contrib/dlz/modules/mysqldyn/dlz_mysqldyn_mod.c index 13f99f68f6..9b126fda80 100644 --- a/contrib/dlz/modules/mysqldyn/dlz_mysqldyn_mod.c +++ b/contrib/dlz/modules/mysqldyn/dlz_mysqldyn_mod.c @@ -1304,9 +1304,21 @@ dlz_newversion(const char *zone, void *dbdata, void **versionp) { * Create new transaction */ newtx = (mysql_transaction_t *) - malloc(sizeof(mysql_transaction_t)); + calloc(1, sizeof(mysql_transaction_t)); + if (newtx == NULL) { + result = ISC_R_NOMEMORY; + goto cleanup; + } newtx->zone = strdup(zone); + if (newtx->zone == NULL) { + result = ISC_R_NOMEMORY; + goto cleanup; + } newtx->zone_id = strdup(zone_id); + if (newtx->zone_id == NULL) { + result = ISC_R_NOMEMORY; + goto cleanup; + } newtx->dbi = get_dbi(state); newtx->next = NULL; @@ -1336,9 +1348,15 @@ dlz_newversion(const char *zone, void *dbdata, void **versionp) { *versionp = (void *) newtx; } else { dlz_mutex_unlock(&state->tx_mutex); - free(newtx->zone); - free(newtx->zone_id); - free(newtx); + if (newtx != NULL) { + if (newtx->zone != NULL) { + free(newtx->zone); + } + if (newtx->zone != NULL) { + free(newtx->zone_id); + } + free(newtx); + } } return (result);