summaryrefslogtreecommitdiffstats
path: root/Modules/_ssl.c
diff options
context:
space:
mode:
authorSteve Dower <steve.dower@python.org>2019-09-09 13:48:22 (GMT)
committerGitHub <noreply@github.com>2019-09-09 13:48:22 (GMT)
commit5d695b6b7bcccf5f028cdacd986096de15bc0ca6 (patch)
tree2f6d1cca58d355ad8b0f7c1ccdbd8220a0cb6d01 /Modules/_ssl.c
parent5e053eb98eb0d65a8e0f00b3641f9907198aace3 (diff)
downloadcpython-5d695b6b7bcccf5f028cdacd986096de15bc0ca6.zip
cpython-5d695b6b7bcccf5f028cdacd986096de15bc0ca6.tar.gz
cpython-5d695b6b7bcccf5f028cdacd986096de15bc0ca6.tar.bz2
bpo-37702: Fix SSL's certificate-store leak on Windows (GH-15632)
ssl_collect_certificates function in _ssl.c has a memory leak. Calling CertOpenStore() and CertAddStoreToCollection(), a store's refcnt gets incremented by 2. But CertCloseStore() is called only once and the refcnt leaves 1.
Diffstat (limited to 'Modules/_ssl.c')
-rw-r--r--Modules/_ssl.c1
1 files changed, 1 insertions, 0 deletions
diff --git a/Modules/_ssl.c b/Modules/_ssl.c
index 089aa3b..6f91b48 100644
--- a/Modules/_ssl.c
+++ b/Modules/_ssl.c
@@ -5581,6 +5581,7 @@ ssl_collect_certificates(const char *store_name)
if (result) {
++storesAdded;
}
+ CertCloseStore(hSystemStore, 0); /* flag must be 0 */
}
}
if (storesAdded == 0) {