Fedora Account System
Red Hat Associate
Red Hat Customer
_CheckSetDoodad() allocates doodad->text.text via _GetCountedString() and then attempts to allocate doodad->text.font. If the font string allocation fails (e.g. because the font string length extends past the request boundary), the error handler frees doodad->text.text but does not NULL the pointer. The doodad was already added to the geometry by XkbAddGeomDoodad() before the string allocations, so when XkbFreeGeometry() runs cleanup, _XkbClearDoodad() frees the same dangling pointer again, resulting in a double-free. NULL the pointer after freeing it to prevent the double-free. This vulnerability was discovered by: Anonymous working with TrendAI Zero Day Initiative ZDI-CAN-31221