[openssl/openssl] d43bf5: quic: fix keyslot cctx leak by not checking EL sta...
"'Jakub Zelenka' via openssl-commits" <[email protected]>
| Newsgroups | gmane.comp.encryption.openssl.cvs |
|---|---|
| Message-ID | <openssl/openssl/push/refs/heads/openssl-3.6/[email protected]> |
Branch: refs/heads/openssl-3.6
Home: https://github.com/openssl/openssl
Commit: d43bf5cab7f05a531636fc0ff45debe7cb3b4f26
https://github.com/openssl/openssl/commit/d43bf5cab7f05a531636fc0ff45debe7cb3b4f26
Author: Jakub Zelenka <[email protected]>
Date: 2026-06-01 (Mon, 01 Jun 2026)
Changed paths:
M ssl/quic/quic_record_shared.c
Log Message:
-----------
quic: fix keyslot cctx leak by not checking EL state in teardown
el_teardown_keyslot() decided whether to free a keyslot by calling
ossl_qrl_enc_level_set_has_keyslot() against the EL's current state.
On error paths the state does not yet match the slots that were
provisioned, so the check returned 0 and the cctx and iv were leaked.
The fix drops the state check and rely on the existing cctx != NULL
check which is sufficient for all callers of el_teardown_keyslot().
Reviewed-by: Matt Caswell <[email protected]>
Reviewed-by: Tomas Mraz <[email protected]>
Reviewed-by: Saša Nedvědický <[email protected]>
MergeDate: Mon Jun 1 07:32:58 2026
(Merged from https://github.com/openssl/openssl/pull/31323)
To unsubscribe from these emails, change your notification settings at https://github.com/openssl/openssl/settings/notifications
--
You received this message because you are subscribed to the Google Groups "openssl-commits" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-commits/openssl/openssl/push/refs/heads/openssl-3.6/4a308b-d43bf5%40github.com.