Repository navigation
BlackDuck scan reports this as a Use After Free Vulnerability #14652
Answered
by
chrisglein
kumaran (kumaran-id-git)
asked this question in
Q&A
|
Static Scan by BlackDuck reports this as a Use After Free Vulnerability // "this->Mso::Futures::FutureCallback::~FutureCallback()" manually destructs "this". |
Answered by
chrisglein
May 8, 2025
Replies: 1 comment
|
Interesting find. Here's the specific line: Invoking the destructor won't actually release the object. It's a little strange, but not necessarily wrong. But... worth looking at! Vladimir Morozov (@vmoroz) give this a look? |
0 replies
Answer selected by
chrisglein
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Interesting find. Here's the specific line:
https://github.com/microsoft/react-native-windows/blame/cc126e4e42ed2dea020655264af0cfb5b1d6ea12/vnext/Mso/src/future/futureImpl.cpp#L1006
Invoking the destructor won't actually release the object. It's a little strange, but not necessarily wrong. But... worth looking at! Vladimir Morozov (@vmoroz) give this a look?