[Date Prev][Date Next] [Thread Prev][Thread Next] [Date Index] [Thread Index]

Bug#971915: buster-pu: package transmission/2.94-2+deb10u2



Package: release.debian.org
Severity: normal
Tags: buster
User: release.debian.org@packages.debian.org
Usertags: pu
X-Debbugs-Cc: morph@debian.org

[ Reason ]
Fixes a memory leak when running Transmission in daemon mode.

[ Tests ]
Have been using the package since a few weeks and the user
who reported the leak (running an affected setup) confirmed
that it fixes the leak.

Cheers,
        Moritz
diff -Nru transmission-2.94/debian/changelog transmission-2.94/debian/changelog
--- transmission-2.94/debian/changelog	2020-05-29 00:05:53.000000000 +0200
+++ transmission-2.94/debian/changelog	2020-08-31 20:43:20.000000000 +0200
@@ -1,3 +1,9 @@
+transmission (2.94-2+deb10u2) buster; urgency=medium
+
+  * Fix mem leak (Closes: #968097)
+
+ -- Moritz Mühlenhoff <jmm@debian.org>  Mon, 31 Aug 2020 20:43:20 +0200
+
 transmission (2.94-2+deb10u1) buster; urgency=medium
 
   * CVE-2018-10756 (Closes: #961461)
diff -Nru transmission-2.94/debian/patches/CVE-2018-10756-2.patch transmission-2.94/debian/patches/CVE-2018-10756-2.patch
--- transmission-2.94/debian/patches/CVE-2018-10756-2.patch	1970-01-01 01:00:00.000000000 +0100
+++ transmission-2.94/debian/patches/CVE-2018-10756-2.patch	2020-08-31 20:43:15.000000000 +0200
@@ -0,0 +1,16 @@
+Fixes mem leak introduced in backport for CVE-2018-10756
+
+--- transmission-2.94.orig/libtransmission/variant.c
++++ transmission-2.94/libtransmission/variant.c
+@@ -873,7 +873,10 @@ static void
+ nodeDestruct (struct SaveNode * node)
+ {
+   if (node->v == node->sorted)
+-    tr_free (node->sorted->val.l.vals);
++    {
++      tr_free (node->sorted->val.l.vals);
++      tr_free (node->sorted);
++    }
+ }
+ 
+ /**
diff -Nru transmission-2.94/debian/patches/series transmission-2.94/debian/patches/series
--- transmission-2.94/debian/patches/series	2020-05-29 00:05:53.000000000 +0200
+++ transmission-2.94/debian/patches/series	2020-08-31 20:42:50.000000000 +0200
@@ -5,3 +5,4 @@
 ayatana-indicators.patch
 patch-vendored-libdht.patch
 CVE-2018-10756.patch
+CVE-2018-10756-2.patch

Reply to: