patch 9.0.1093: using freed memory of object member
Problem: Using freed memory of object member. (Yegappan Lakshmanan)
Solution: Make a copy of the object member when getting it.
diff --git a/src/vim9execute.c b/src/vim9execute.c
index cdaeb5b..a6d43b5 100644
--- a/src/vim9execute.c
+++ b/src/vim9execute.c
@@ -3799,7 +3799,7 @@
tv->vval.v_number = iptr->isn_arg.storenr.stnr_val;
break;
- // store value in list or dict variable
+ // Store a value in a list, dict, blob or object variable.
case ISN_STOREINDEX:
{
int res = execute_storeindex(iptr, ectx);
@@ -5159,7 +5159,7 @@
object_T *obj = tv->vval.v_object;
// the members are located right after the object struct
typval_T *mtv = ((typval_T *)(obj + 1)) + idx;
- *tv = *mtv;
+ copy_tv(mtv, tv);
// Unreference the object after getting the member, it may
// be freed.