On Fri, 25 Sep 2026 13:50:35 GMT, Matthias Baesken <[email protected]> wrote:

> In Java_sun_net_www_protocol_http_ntlm_NTLMAuthSequence_getCredentialsHandle, 
> a CredHandle struct is allocated with a malloc call.
> But the malloced memory is never freed if later in the same function the 
> AcquireCredentialsHandleA call fails.
> 
> ---------
> - [x] I confirm that I make this contribution in accordance with the [OpenJDK 
> Interim AI Policy](https://openjdk.org/legal/ai).

src/java.base/windows/native/libnet/NTLMAuthSequence.c line 145:

> 143:         return (jlong) pCred;
> 144:     } else {
> 145:         if (pCred != NULL) free(pCred);

the NULL check is not necessary, `free` checks for NULL too.

-------------

PR Review Comment: https://git.openjdk.org/jdk/pull/33070#discussion_r4119027036

Reply via email to