Fix a potential double free in EVP_DigestInit_ex
There is a potential double free in EVP_DigestInit_ex. This is believed to be reached only as a result of programmer error - but we should fix it anyway. Issue reported by Guido Vranken. Reviewed-by: Richard Levitte <levitte@openssl.org> (cherry picked from commit ffe9150b1508a0ffc9e724f975691f24eb045c05)
This commit is contained in:
parent
4256957570
commit
e78dc7e279
@ -212,8 +212,10 @@ int EVP_DigestInit_ex(EVP_MD_CTX *ctx, const EVP_MD *type, ENGINE *impl)
|
|||||||
}
|
}
|
||||||
#endif
|
#endif
|
||||||
if (ctx->digest != type) {
|
if (ctx->digest != type) {
|
||||||
if (ctx->digest && ctx->digest->ctx_size)
|
if (ctx->digest && ctx->digest->ctx_size) {
|
||||||
OPENSSL_free(ctx->md_data);
|
OPENSSL_free(ctx->md_data);
|
||||||
|
ctx->md_data = NULL;
|
||||||
|
}
|
||||||
ctx->digest = type;
|
ctx->digest = type;
|
||||||
if (!(ctx->flags & EVP_MD_CTX_FLAG_NO_INIT) && type->ctx_size) {
|
if (!(ctx->flags & EVP_MD_CTX_FLAG_NO_INIT) && type->ctx_size) {
|
||||||
ctx->update = type->update;
|
ctx->update = type->update;
|
||||||
|
Loading…
x
Reference in New Issue
Block a user