server: Delay destruction of file object in set_irp_result.
sebastian at fds-team.de
Thu Jun 18 21:36:21 CDT 2015
Under specific situations calling set_irp_result can cause a wineserver crash
because the function assumes, that irp->file has a refcount greater than 1.
The call to 'release_object( file );' can destroy the associated file, but
later 'list_remove( &irp->dev_entry );' is executed which assumes that the
file still exists.
-------------- next part --------------
A non-text attachment was scrubbed...
Size: 1012 bytes
Desc: not available
More information about the wine-patches