On Fri, 25 Sep 2026 13:50:35 GMT, Matthias Baesken <[email protected]> wrote:

> In Java_sun_net_www_protocol_http_ntlm_NTLMAuthSequence_getCredentialsHandle, 
> a CredHandle struct is allocated with a malloc call.
> But the malloced memory is never freed if later in the same function the 
> AcquireCredentialsHandleA call fails.
> 
> ---------
> - [x] I confirm that I make this contribution in accordance with the [OpenJDK 
> Interim AI Policy](https://openjdk.org/legal/ai).

other point, regarding
`CHECK_NULL_RETURN(pInput, NULL);`
in Java_sun_net_www_protocol_http_ntlm_NTLMAuthSequence_getNextToken  in the 
same file - can this leak malloced newContext , or will this never happen 
because of some constraints or later freeing somewhere else?

-------------

PR Comment: https://git.openjdk.org/jdk/pull/33070#issuecomment-5893614737

Reply via email to