Skip to content

Commit 0c5069f

Browse files
authored
Guard against crash when sk_CRYPTO_BUFFER_new_null() returns NULL (#1007)
Motivation: When out of memory sk_CRYPTO_BUFFER_new_null() will return NULL, so we should better guard against it as otherwise we might crash Modifications: Check for NULL and handle it Result: More robust code even when out of memory
1 parent f234e92 commit 0c5069f

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

‎openssl-dynamic/src/main/c/sslutils.c‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -473,6 +473,9 @@ static int SSL_CTX_setup_certs(SSL_CTX *ctx, BIO *bio, bool skipfirst, bool ca)
473473
{
474474
#if defined(OPENSSL_IS_BORINGSSL) || defined(OPENSSL_IS_AWSLC)
475475
STACK_OF(CRYPTO_BUFFER) *names = sk_CRYPTO_BUFFER_new_null();
476+
if (names == NULL) {
477+
return -1;
478+
}
476479
CRYPTO_BUFFER *buffer = NULL;
477480
uint8_t *outp = NULL;
478481
int len;

0 commit comments

Comments
 (0)