36 lines
1.1 KiB
Diff
36 lines
1.1 KiB
Diff
From d07e8b0ae66e96cda9c803de36e977fb7dfe941a Mon Sep 17 00:00:00 2001
|
|
From: "Dr. Matthias St. Pierre" <matthias.st.pierre@ncp-e.com>
|
|
Date: Wed, 6 May 2020 17:24:13 +0200
|
|
Subject: [PATCH 044/217] Fix use-after-free in BIO_C_SET_SSL callback
|
|
|
|
Since the BIO_SSL structure was renewed by `ssl_free(b)/ssl_new(b)`,
|
|
the `bs` pointer needs to be updated before assigning to `bs->ssl`.
|
|
|
|
Thanks to @suishixingkong for reporting the issue and providing a fix.
|
|
|
|
Closes #10539
|
|
|
|
Reviewed-by: Tomas Mraz <tmraz@fedoraproject.org>
|
|
(Merged from https://github.com/openssl/openssl/pull/11746)
|
|
|
|
(cherry picked from commit 73d6b4efe6835a6c97ce61df6bf339b0903e5b7a)
|
|
---
|
|
ssl/bio_ssl.c | 1 +
|
|
1 file changed, 1 insertion(+)
|
|
|
|
diff --git a/ssl/bio_ssl.c b/ssl/bio_ssl.c
|
|
index ab9e666..efa23bf 100644
|
|
--- a/ssl/bio_ssl.c
|
|
+++ b/ssl/bio_ssl.c
|
|
@@ -284,6 +284,7 @@ static long ssl_ctrl(BIO *b, int cmd, long num, void *ptr)
|
|
ssl_free(b);
|
|
if (!ssl_new(b))
|
|
return 0;
|
|
+ bs = BIO_get_data(b);
|
|
}
|
|
BIO_set_shutdown(b, num);
|
|
ssl = (SSL *)ptr;
|
|
--
|
|
1.8.3.1
|
|
|