Skip to content

harden: fix use-after-free in odbc_cursor.cpp (CWE-416) - #495

Open
anupamme wants to merge 1 commit into
IBM:mainfrom
anupamme:fix-repo-node-odbc-cwe-416-odbc-cursor-uaf
Open

anupamme wants to merge 1 commit into
IBM:mainfrom
anupamme:fix-repo-node-odbc-cwe-416-odbc-cursor-uaf

Conversation

@anupamme

Copy link
Copy Markdown

The destructor calls Free() which deallocates cursor resources. If another thread or async callback is still accessing the cursor, a use-after-free condition occurs where freed memory is accessed, potentially enabling memory corruption. This is defence-in-depth at src/odbc_cursor.cpp:54 rather than a vulnerability I can show is exploitable here — it makes the failure mode explicit and bounded. Close it freely if the pattern is intentional.

Reference: CWE-416

What changed

  • src/odbc_cursor.cpp

Verification

No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.


Automated security fix by OrbisAI Security

Automated security fix generated by OrbisAI Security
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant