[neon/backports-noble/wayland-noble/Neon/release] src: util: fix use-after-free in for_each_helper

YaNing Lu null at kde.org
Sat Aug 22 05:55:34 BST 2026


Git commit e647f6304d7491fa436047908dc559f5badf613e by YaNing Lu.
Committed on 30/03/2026 at 00:52.
Pushed by carlosdem into branch 'Neon/release'.

util: fix use-after-free in for_each_helper

for_each_helper caches the entries->data pointer and array size before
iterating. If a compositor calls wl_client_for_each_resource() and the
provided callback triggers the creation of a new client object, the
underlying wl_array may be reallocated via realloc().

When this happens, the cached start pointer becomes dangling. Subsequent
iterations will read from the freed memory block, causing already-destroyed
resources to be destroyed a second time (e.g., leading to a double-free
crash in wl_list_remove()).

Fix this by dynamically re-fetching entries->data and entries->size on
every loop iteration, ensuring the iterator always accesses the valid
live array.

Signed-off-by: YaNing Lu <luyaning at uniontech.com>

M  +5    -3    src/wayland-util.c

https://invent.kde.org/neon/backports-noble/wayland-noble/-/commit/e647f6304d7491fa436047908dc559f5badf613e

diff --git a/src/wayland-util.c b/src/wayland-util.c
index f551867..15e157d 100644
--- a/src/wayland-util.c
+++ b/src/wayland-util.c
@@ -424,10 +424,12 @@ for_each_helper(struct wl_array *entries, wl_iterator_func_t func, void *data)
 	union map_entry entry, *start;
 	size_t count;
 
-	start = (union map_entry *) entries->data;
-	count = entries->size / sizeof(union map_entry);
+	for (size_t idx = 0; ; idx++) {
+		count = entries->size / sizeof(union map_entry);
+		if (idx >= count)
+			break;
 
-	for (size_t idx = 0; idx < count; idx++) {
+		start = (union map_entry *) entries->data;
 		entry = start[idx];
 		if (entry.data && !map_entry_is_free(entry)) {
 			ret = func(map_entry_get_data(entry), data, map_entry_get_flags(entry));



More information about the Neon-commits mailing list