Skip to content

Fix: free overwritten multi-handle headers - #1141

Merged
greenbonebot merged 2 commits into
mainfrom
fix/71-conn-stream-resp-multi-handler-headers-customheader-overwrites-multi-handle-heade
Oct 6, 2026
Merged

greenbonebot merged 2 commits into
mainfrom
fix/71-conn-stream-resp-multi-handler-headers-customheader-overwrites-multi-handle-heade

Conversation

@mattmundell

Copy link
Copy Markdown
Contributor

What

Free the multi_handle->headers before overwriting it with the caller's
customheader in http_scanner_init_request_multi (http_scanner.c).

Why

Assigning customheader straight over multi_handle->headers discarded the
gvm_http_headers_t that gvm_http_multi_new had just allocated internally,
so that allocation was never freed and leaked on every successful call.

Like /pull/1140 gvmd only does the init once, but might as well clean up.

Testing

  • http_scanner_init_request_multi_replaces_multi_headers (http-scanner-test):
    before the fix, LeakSanitizer reported an 8-byte direct leak allocated by
    gvm_http_headers_new (http/httputils.c:666) from gvm_http_multi_new;
    after, the case passes with no leak report.

gvm_http_multi_new allocated multi->headers and the assignment
discarded that pointer, leaking the gvm_http_headers_t on every
successful call.
@mattmundell
mattmundell requested review from a team as code owners October 6, 2026 10:43
@greenbonebot
greenbonebot enabled auto-merge (rebase) October 6, 2026 10:44
@github-actions

github-actions Bot commented Oct 6, 2026

Copy link
Copy Markdown

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA 39d7fa9.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

Scanned Files

None

@greenbonebot
greenbonebot merged commit 9ed1a08 into main Oct 6, 2026
22 checks passed
@greenbonebot
greenbonebot deleted the fix/71-conn-stream-resp-multi-handler-headers-customheader-overwrites-multi-handle-heade branch October 6, 2026 12:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants