Jeff Hutzelman points out that RFC2744 specifically requires that all gss_buffer_t outputs be released. That wouldn't bother me at all here (we'd have to say that draft-ietf-sasl-gs2 updates RFC2744), but, RFC5587 (draft-ietf-kitten-extended-mech-inquiry, in AUTH48) had a chance to do that and didn't, so I'd say that these output buffers should be released by the app.