From 6d3c9c8ab4754ea21622d65f11df403bbaf46e2d Mon Sep 17 00:00:00 2001 From: Daniel Stenberg Date: Wed, 18 Apr 2018 23:51:01 +0200 Subject: [PATCH] http2: handle on_begin_headers() called more than once This triggered an assert if called more than once in debug mode (and a memory leak if not debug build). With the right sequence of HTTP/2 headers incoming it can happen. Detected by OSS-Fuzz Closes #2507 Bug: https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=7764 --- lib/http2.c | 12 ++++-------- 1 file changed, 4 insertions(+), 8 deletions(-) diff --git a/lib/http2.c b/lib/http2.c index 6758f9554..e60ae247b 100644 --- a/lib/http2.c +++ b/lib/http2.c @@ -870,16 +870,12 @@ static int on_begin_headers(nghttp2_session *session, return 0; } - /* This is trailer HEADERS started. Allocate buffer for them. */ - H2BUGF(infof(data_s, "trailer field started\n")); - - DEBUGASSERT(stream->trailer_recvbuf == NULL); - - stream->trailer_recvbuf = Curl_add_buffer_init(); if(!stream->trailer_recvbuf) { - return NGHTTP2_ERR_TEMPORAL_CALLBACK_FAILURE; + stream->trailer_recvbuf = Curl_add_buffer_init(); + if(!stream->trailer_recvbuf) { + return NGHTTP2_ERR_TEMPORAL_CALLBACK_FAILURE; + } } - return 0; }