From: LorenzoPegorari Date: Tue, 19 May 2026 14:54:45 GMT Subject: [PATCH] http: fix memory leak in fetch_and_setup_pack_index() Message-ID: Inside the function `fetch_and_setup_pack_index()`, when the pack obtained using `fetch_pack_index()` fails to be verified by `parse_pack_index()`, the function returns without closing and freeing said pack. Fix this by calling `close_pack_index()` to munmap the index file for the leaking pack (which might have been mmapped by `fetch_pack_index()` or `verify_pack_index()`), and then free it. Signed-off-by: LorenzoPegorari --- http.c | 8 +++++--- 1 file changed, 5 insertions(+), 3 deletions(-) diff --git a/http.c b/http.c index 67c9c6fc60..c28be26ad9 100644 --- a/http.c +++ b/http.c @@ -2545,11 +2545,13 @@ static int fetch_and_setup_pack_index(struct packfile_list *packs, } ret = verify_pack_index(new_pack); - if (!ret) - close_pack_index(new_pack); + + close_pack_index(new_pack); free(tmp_idx); - if (ret) + if (ret) { + free(new_pack); return -1; + } packfile_list_prepend(packs, new_pack); return 0; -- 2.54.0.dirty