From a92581acf2aba5e5e9fa199b778e649d5741754d Mon Sep 17 00:00:00 2001 From: Carl Worth Date: Thu, 13 Feb 2014 09:49:27 -0800 Subject: main: Avoid double-free of shader Label As documented, the _mesa_free_shader_program_data function: "Frees all the data that hangs off a shader program object, but not the object itself." This means that this function may be called multiple times on the same object, (and has been observed to). Meanwhile, the shProg->Label field was not being set to NULL after its free(). This led to a second call to free() of the same address on the second call to this function. Fix this by setting this field to NULL after free(), (just as with all other calls to free() in this function). Reviewed-by: Brian Paul CC: mesa-stable@lists.freedesktop.org --- src/mesa/main/shaderobj.c | 1 + 1 file changed, 1 insertion(+) (limited to 'src/mesa') diff --git a/src/mesa/main/shaderobj.c b/src/mesa/main/shaderobj.c index 4f4bb69a872..d5c3d8099a7 100644 --- a/src/mesa/main/shaderobj.c +++ b/src/mesa/main/shaderobj.c @@ -355,6 +355,7 @@ _mesa_free_shader_program_data(struct gl_context *ctx, } free(shProg->Label); + shProg->Label = NULL; } -- cgit v1.2.3