Skip to content

Commit 86a3c0f

Browse files
committed
Motivation:
A double DeleteLocalRef on the same local reference is present in both the OpenSSL and BoringSSL cert-verify callbacks in sslcontext.c. The NETTY_JNI_UTIL_DELETE_LOCAL macro does not null out the pointer after deleting , so a second delete on the same stale handle is real UB per the JNI spec — it can corrupt the local-ref table and crash later in an unrelated JNI call. This regression was introduces by 990751e Modifications: Remove deletion of local ref when its already done Result: No more UB
1 parent 3bf8d04 commit 86a3c0f

1 file changed

Lines changed: 0 additions & 4 deletions

File tree

‎openssl-dynamic/src/main/c/sslcontext.c‎

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -1637,8 +1637,6 @@ static int SSL_cert_verify(X509_STORE_CTX *ctx, void *arg) {
16371637

16381638
result = (*e)->CallIntMethod(e, c->verifier, c->verifier_method, P2J(ssl), array, authMethodString);
16391639

1640-
NETTY_JNI_UTIL_DELETE_LOCAL(e, authMethodString);
1641-
16421640
if ((*e)->ExceptionCheck(e)) {
16431641
// We always need to set the error as stated in the SSL_CTX_set_cert_verify_callback manpage, so set the result
16441642
// to the correct value.
@@ -1769,8 +1767,6 @@ enum ssl_verify_result_t tcn_SSL_cert_custom_verify(SSL* ssl, uint8_t *out_alert
17691767
// Execute the java callback
17701768
result = (*e)->CallIntMethod(e, state->ctx->verifier, state->ctx->verifier_method, P2J(ssl), array, authMethodString);
17711769

1772-
NETTY_JNI_UTIL_DELETE_LOCAL(e, authMethodString);
1773-
17741770
if ((*e)->ExceptionCheck(e) == JNI_TRUE) {
17751771
result = X509_V_ERR_UNSPECIFIED;
17761772
goto complete;

0 commit comments

Comments
 (0)