# HG changeset patch # User Christian Brabandt # Date 1538166606 -7200 # Node ID 85ef79b16181ec0dced53f36d90ffd3bd0d84b4b # Parent c2d0417c7f199ddf72fdbe0c3796481c26b17068 patch 8.1.0437: may access freed memory when syntax HL times out commit https://github.com/vim/vim/commit/95892c27b242cdbc78e622c7a861a4e15aec7a30 Author: Bram Moolenaar Date: Fri Sep 28 22:26:54 2018 +0200 patch 8.1.0437: may access freed memory when syntax HL times out Problem: May access freed memory when syntax HL times out. (Philipp Gesang) Solution: Clear b_sst_first when clearing b_sst_array. diff --git a/src/syntax.c b/src/syntax.c --- a/src/syntax.c +++ b/src/syntax.c @@ -1192,6 +1192,7 @@ syn_stack_free_block(synblock_T *block) for (p = block->b_sst_first; p != NULL; p = p->sst_next) clear_syn_state(p); VIM_CLEAR(block->b_sst_array); + block->b_sst_first = NULL; block->b_sst_len = 0; } } @@ -1323,9 +1324,6 @@ syn_stack_apply_changes_block(synblock_T synstate_T *p, *prev, *np; linenr_T n; - if (block->b_sst_array == NULL) /* nothing to do */ - return; - prev = NULL; for (p = block->b_sst_first; p != NULL; ) { @@ -1378,7 +1376,7 @@ syn_stack_cleanup(void) int dist; int retval = FALSE; - if (syn_block->b_sst_array == NULL || syn_block->b_sst_first == NULL) + if (syn_block->b_sst_first == NULL) return retval; /* Compute normal distance between non-displayed entries. */ diff --git a/src/version.c b/src/version.c --- a/src/version.c +++ b/src/version.c @@ -795,6 +795,8 @@ static char *(features[]) = static int included_patches[] = { /* Add new patch number below this line */ /**/ + 437, +/**/ 436, /**/ 435,