Skip to content

Commit 3f1724d

Browse files
authored
Check if hostname matcher is NULL and if so return early (#1004)
Motivation: We should better check if the matcher is NULL before trying to invoke it as it might be set to NULL while the handshake is still in flight Modifications: Add NULL check Result: Safer code
1 parent 877d622 commit 3f1724d

1 file changed

Lines changed: 3 additions & 0 deletions

File tree

‎openssl-dynamic/src/main/c/sslcontext.c‎

Lines changed: 3 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2602,6 +2602,9 @@ static int ssl_servername_cb(SSL *ssl, int *ad, void *arg)
26022602

26032603
const char *servername = SSL_get_servername(ssl, TLSEXT_NAMETYPE_host_name);
26042604
if (servername != NULL) {
2605+
if (c->sni_hostname_matcher == NULL) {
2606+
return SSL_TLSEXT_ERR_OK;
2607+
}
26052608
if (tcn_get_java_env(&e) != JNI_OK) {
26062609
return SSL_TLSEXT_ERR_ALERT_FATAL;
26072610
}

0 commit comments

Comments
 (0)