Sitelet https://github.com/ParallelSSH/libssh2/commit/8d3bc19b3b53e791699685bb9adbcfef95fabb59
Skip to content

Commit 8d3bc19

Browse files
authored
Fix memory leaks in _libssh2_ecdsa_curve_name_with_octal_new and _libssh2_ecdsa_verify (libssh2#1449)
Better error handling in`_libssh2_ecdsa_curve_name_with_octal_new` and `_libssh2_ecdsa_verify` to prevent leaks. Credit: dksslq <dksslq@github.com>
1 parent de00487 commit 8d3bc19

1 file changed

Lines changed: 53 additions & 13 deletions

File tree

‎src/openssl.c‎

Lines changed: 53 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -798,6 +798,9 @@ _libssh2_ecdsa_curve_name_with_octal_new(libssh2_ecdsa_ctx ** ec_ctx,
798798
char *group_name = NULL;
799799
unsigned char *data = NULL;
800800

801+
if(!ctx)
802+
return -1;
803+
801804
if(n) {
802805
group_name = OPENSSL_zalloc(strlen(n) + 1);
803806
}
@@ -822,17 +825,22 @@ _libssh2_ecdsa_curve_name_with_octal_new(libssh2_ecdsa_ctx ** ec_ctx,
822825

823826
params[2] = OSSL_PARAM_construct_end();
824827

825-
if(EVP_PKEY_fromdata_init(ctx) > 0) {
828+
if(EVP_PKEY_fromdata_init(ctx) > 0)
826829
ret = EVP_PKEY_fromdata(ctx, ec_ctx, EVP_PKEY_PUBLIC_KEY,
827830
params);
828-
}
831+
else
832+
ret = -1;
833+
}
834+
else
835+
ret = -1;
829836

830-
if(group_name)
831-
OPENSSL_clear_free(group_name, strlen(n));
837+
if(group_name)
838+
OPENSSL_clear_free(group_name, strlen(n));
832839

833-
if(data)
834-
OPENSSL_clear_free(data, k_len);
835-
}
840+
if(data)
841+
OPENSSL_clear_free(data, k_len);
842+
843+
EVP_PKEY_CTX_free(ctx);
836844
#else
837845
EC_KEY *ec_key = EC_KEY_new_by_curve_name(curve);
838846

@@ -842,15 +850,26 @@ _libssh2_ecdsa_curve_name_with_octal_new(libssh2_ecdsa_ctx ** ec_ctx,
842850

843851
ec_group = EC_KEY_get0_group(ec_key);
844852
point = EC_POINT_new(ec_group);
845-
ret = EC_POINT_oct2point(ec_group, point, k, k_len, NULL);
846-
ret = EC_KEY_set_public_key(ec_key, point);
847853

848-
if(point)
854+
if(point) {
855+
ret = EC_POINT_oct2point(ec_group, point, k, k_len, NULL);
856+
if(ret == 1)
857+
ret = EC_KEY_set_public_key(ec_key, point);
858+
849859
EC_POINT_free(point);
860+
}
861+
else
862+
ret = -1;
850863

851-
if(ec_ctx)
864+
if(ret == 1 && ec_ctx)
852865
*ec_ctx = ec_key;
866+
else {
867+
EC_KEY_free(ec_key);
868+
ret = -1;
869+
}
853870
}
871+
else
872+
ret = -1;
854873
#endif
855874

856875
return (ret == 1) ? 0 : -1;
@@ -916,7 +935,16 @@ _libssh2_ecdsa_verify(libssh2_ecdsa_ctx * ecdsa_ctx,
916935

917936
#ifdef USE_OPENSSL_3
918937
ctx = EVP_PKEY_CTX_new(ecdsa_ctx, NULL);
938+
if(!ctx) {
939+
ret = -1;
940+
goto cleanup;
941+
}
942+
919943
der_len = i2d_ECDSA_SIG(ecdsa_sig, &der);
944+
if(der_len <= 0) {
945+
ret = -1;
946+
goto cleanup;
947+
}
920948
#endif
921949

922950
if(type == LIBSSH2_EC_CURVE_NISTP256) {
@@ -929,12 +957,24 @@ _libssh2_ecdsa_verify(libssh2_ecdsa_ctx * ecdsa_ctx,
929957
LIBSSH2_ECDSA_VERIFY(512);
930958
}
931959

960+
#ifdef USE_OPENSSL_3
961+
cleanup:
962+
963+
if(ctx)
964+
EVP_PKEY_CTX_free(ctx);
965+
966+
if(der)
967+
OPENSSL_free(der);
968+
#endif
969+
932970
#ifdef HAVE_OPAQUE_STRUCTS
933971
if(ecdsa_sig)
934972
ECDSA_SIG_free(ecdsa_sig);
935973
#else
936-
BN_clear_free(ecdsa_sig_.s);
937-
BN_clear_free(ecdsa_sig_.r);
974+
if(ecdsa_sig_.s)
975+
BN_clear_free(ecdsa_sig_.s);
976+
if(ecdsa_sig_.r)
977+
BN_clear_free(ecdsa_sig_.r);
938978
#endif
939979

940980
return (ret == 1) ? 0 : -1;

0 commit comments

Comments
 (0)