[openssl/openssl] bee839: quic: fix keyslot cctx leak by not checking EL sta...
"'Jakub Zelenka' via openssl-commits" <[email protected]>
| Newsgroups | gmane.comp.encryption.openssl.cvs |
|---|---|
| Message-ID | <openssl/openssl/push/refs/heads/openssl-4.0/[email protected]> |
Branch: refs/heads/openssl-4.0
Home: https://github.com/openssl/openssl
Commit: bee83928d2daa672eaa774c7f11dd3b9440fc35b
https://github.com/openssl/openssl/commit/bee83928d2daa672eaa774c7f11dd3b9440fc35b
Author: Jakub Zelenka <[email protected]>
Date: 2026-06-01 (Mon, 01 Jun 2026)
Changed paths:
M ssl/quic/quic_record_shared.c
Log Message:
-----------
quic: fix keyslot cctx leak by not checking EL state in teardown
el_teardown_keyslot() decided whether to free a keyslot by calling
ossl_qrl_enc_level_set_has_keyslot() against the EL's current state.
On error paths the state does not yet match the slots that were
provisioned, so the check returned 0 and the cctx and iv were leaked.
The fix drops the state check and rely on the existing cctx != NULL
check which is sufficient for all callers of el_teardown_keyslot().
Reviewed-by: Matt Caswell <[email protected]>
Reviewed-by: Tomas Mraz <[email protected]>
Reviewed-by: Saša Nedvědický <[email protected]>
MergeDate: Mon Jun 1 07:33:07 2026
(Merged from https://github.com/openssl/openssl/pull/31323)
To unsubscribe from these emails, change your notification settings at https://github.com/openssl/openssl/settings/notifications
--
You received this message because you are subscribed to the Google Groups "openssl-commits" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-commits/openssl/openssl/push/refs/heads/openssl-4.0/f363e2-bee839%40github.com.