Conversation
create_local_bg_thread() holds a reference to the printer via
printer->use while it generates the IPP Everywhere PPD.
cupsdDeleteTemporaryPrinters() respected that reference, but
cupsdDeletePrinter() did not, so an explicit CUPS-Delete-Printer (as
cups-browsed issues when it replaces a discovered queue) freed the
printer mid-thread and corrupted the heap ("corrupted double-linked
list").
Defer deletion while printer->use > 0 by flagging the printer under
printer->lock; cupsdDeleteTemporaryPrinters() then reaps it once the
thread releases its reference. Extends the use-count protection from
OpenPrinting#1655 to the explicit deletion path.
|
CI may need this first #1723 |
michaelrsweet
left a comment
There was a problem hiding this comment.
I think we can simply this to just decrement use to 0 but not immediately delete it. Will think some, and we should bring this fix to 2.4.x as well.
|
OK, my fixes: [master 4bfa89a] Fix potential scheduler printer use-after-free bug (Issue #1722) [2.4.x eb06fe2] Fix potential scheduler printer use-after-free bug (Issue #1722) Basically, I initialize "use" to 1 in |
create_local_bg_thread() holds a reference to the printer via printer->use while it generates the IPP Everywhere PPD. cupsdDeleteTemporaryPrinters() respected that reference, but cupsdDeletePrinter() did not, so an explicit CUPS-Delete-Printer (as cups-browsed issues when it replaces a discovered queue) freed the printer mid-thread and corrupted the heap ("corrupted double-linked list").
Defer deletion while printer->use > 0 by flagging the printer under printer->lock; cupsdDeleteTemporaryPrinters() then reaps it once the thread releases its reference. Extends the use-count protection from #1655 to the explicit deletion path.