From e4d50cf7310771173e024211a64b4c05ef14674f Mon Sep 17 00:00:00 2001 From: DawnFire42 Date: Thu, 9 Jul 2026 14:21:04 -0400 Subject: [PATCH] Fix use-after-free in CommandZone teardown by disconnecting signals before member destruction --- cockatrice/src/game_graphics/zones/command_zone.cpp | 7 +++++++ cockatrice/src/game_graphics/zones/command_zone.h | 1 + 2 files changed, 8 insertions(+) diff --git a/cockatrice/src/game_graphics/zones/command_zone.cpp b/cockatrice/src/game_graphics/zones/command_zone.cpp index 198a0ac82..6b2b4139b 100644 --- a/cockatrice/src/game_graphics/zones/command_zone.cpp +++ b/cockatrice/src/game_graphics/zones/command_zone.cpp @@ -24,6 +24,13 @@ CommandZone::CommandZone(CommandZoneLogic *_logic, int _zoneHeight, QGraphicsIte setupClipContainer(ZValues::CARD_BASE); } +CommandZone::~CommandZone() +{ + for (AbstractCounter *ctr : taxCounters) { + disconnect(ctr, &QObject::destroyed, this, nullptr); + } +} + void CommandZone::updateBg() { update(); diff --git a/cockatrice/src/game_graphics/zones/command_zone.h b/cockatrice/src/game_graphics/zones/command_zone.h index 4595e7445..6e7d3a619 100644 --- a/cockatrice/src/game_graphics/zones/command_zone.h +++ b/cockatrice/src/game_graphics/zones/command_zone.h @@ -62,6 +62,7 @@ public: * @param parent Parent graphics item */ CommandZone(CommandZoneLogic *_logic, int _zoneHeight, QGraphicsItem *parent); + ~CommandZone() override; /** * @brief Handles card drops, calculating insertion position from drop point.