X11: Fix segfault on malformed INCR response

The code assumed that at least some data would be received via the INCR
mechanism and that, as a result, the string buffer would be allocated.

Bug found by Clang static analysis.

(cherry picked from commit 23e6e8e4b7)
This commit is contained in:
Camilla Löwy 2022-04-18 23:22:25 +02:00
parent 946312fe93
commit 65b8c4a46b
2 changed files with 9 additions and 5 deletions

View File

@ -134,6 +134,7 @@ information on what to include when reporting a bug.
- [Cocoa] Bugfix: A connected Apple AirPlay would emit a useless error (#1791)
- [Cocoa] Bugfix: The EGL and OSMesa libraries were not unloaded on termination
- [X11] Bugfix: The OSMesa libray was not unloaded on termination
- [X11] Bugfix: A malformed response during selection transfer could cause a segfault
- [Wayland] Added support for file path drop events (#2040)
- [Wayland] Bugfix: `glfwSetClipboardString` would fail if set to result of
`glfwGetClipboardString`

View File

@ -1049,13 +1049,16 @@ static const char* getSelectionString(Atom selection)
if (!itemCount)
{
if (targets[i] == XA_STRING)
if (string)
{
*selectionString = convertLatin1toUTF8(string);
free(string);
if (targets[i] == XA_STRING)
{
*selectionString = convertLatin1toUTF8(string);
free(string);
}
else
*selectionString = string;
}
else
*selectionString = string;
break;
}