The branch OpenSSL_1_1_0-stable has been updated
       via  87b315965296273750ab69728648bbff331e1687 (commit)
      from  1d015368ebe245c4468522d152edfd8a1069426e (commit)


- Log -----------------------------------------------------------------
commit 87b315965296273750ab69728648bbff331e1687
Author: Matt Caswell <m...@openssl.org>
Date:   Tue Apr 17 11:32:20 2018 +0100

    Check the return from EVP_PKEY_get0_DH()
    
    Fixes #5934
    
    Reviewed-by: Rich Salz <rs...@openssl.org>
    (Merged from https://github.com/openssl/openssl/pull/5993)

-----------------------------------------------------------------------

Summary of changes:
 ssl/statem/statem_srvr.c | 6 ++++++
 1 file changed, 6 insertions(+)

diff --git a/ssl/statem/statem_srvr.c b/ssl/statem/statem_srvr.c
index c7cd9eb..f216db7 100644
--- a/ssl/statem/statem_srvr.c
+++ b/ssl/statem/statem_srvr.c
@@ -1698,6 +1698,12 @@ int tls_construct_server_key_exchange(SSL *s)
         }
 
         dh = EVP_PKEY_get0_DH(s->s3->tmp.pkey);
+        if (dh == NULL) {
+            al = SSL_AD_INTERNAL_ERROR;
+            SSLerr(SSL_F_TLS_CONSTRUCT_SERVER_KEY_EXCHANGE,
+                   ERR_R_INTERNAL_ERROR);
+            goto err;
+        }
 
         EVP_PKEY_free(pkdh);
         pkdh = NULL;
_____
openssl-commits mailing list
To unsubscribe: https://mta.openssl.org/mailman/listinfo/openssl-commits

Reply via email to