Repository navigation
Conversation
Automated security fix generated by OrbisAI Security
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 20 minutes. View limit detailsLimit details: You’ve used all 2 included reviews currently available. Review configuration: ⚙️ Run configuration
📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
|
Closing. The PR description itself says the change is unverified. Please don't open auto-generated PRs that haven't been verified against a real, reproducible defect — #429 was a genuine fix and was welcome; this and #440 are not. |
|
Thanks for the clarification. You’re right on both points. I missed that aes = NULL / hmac = NULL only updates the local parameter and therefore does not clear the caller’s pointer. More importantly, I didn’t verify that zip_crypto_openssl.c is actually part of the iOS build; with HAVE_COMMONCRYPTO enabled, this finding isn’t applicable to the target platform. I’ll treat this finding as invalid. I’ll make sure future automated findings are verified for both reachability and platform/build configuration before opening a PR. |
The _zip_crypto_aes_free and _zip_crypto_hmac_free functions free memory but do not set the pointer to NULL afterward. In a multi-threaded context or if there's a double-free bug elsewhere, this could lead to use-after-free conditions. The pointer remains dangling after free(), and if accessed again through a race condition, it could cause heap corruption. This is defence-in-depth at
TKLiveSync/libzip/zip_crypto_openssl.c:62rather than a vulnerability I can show is exploitable here — it makes the failure mode explicit and bounded. Close it freely if the pattern is intentional.Reference: CWE-416
What changed
TKLiveSync/libzip/zip_crypto_openssl.cVerification
No automated check could be run against this repository, so this change is unverified beyond review. Please treat it as a suggestion.
Automated security fix by OrbisAI Security