From 476b9edd7a56e6c4f2158863a50ab0a5ac65049a Mon Sep 17 00:00:00 2001 From: Niels Dossche <7771979+nielsdos@users.noreply.github.com> Date: Sat, 24 May 2025 16:19:53 +0200 Subject: [PATCH] Fix memory leaks in php_http.c when call_user_function() fails retval can be refcounted but is not destroyed. --- ext/soap/php_http.c | 2 ++ 1 file changed, 2 insertions(+) diff --git a/ext/soap/php_http.c b/ext/soap/php_http.c index 00aa54c83efdb..c908bb4d8ff16 100644 --- a/ext/soap/php_http.c +++ b/ext/soap/php_http.c @@ -416,6 +416,7 @@ int make_http_soap_request(zval *this_ptr, } else { zval_ptr_dtor(¶ms[0]); zval_ptr_dtor(&func); + zval_ptr_dtor(&retval); if (request != buf) { zend_string_release_ex(request, 0); } @@ -1314,6 +1315,7 @@ int make_http_soap_request(zval *this_ptr, } else { zval_ptr_dtor(¶ms[0]); zval_ptr_dtor(&func); + zval_ptr_dtor(&retval); efree(content_encoding); zend_string_release_ex(http_headers, 0); zend_string_release_ex(http_body, 0);