openssl/ssl
Bernd Edlinger bc0773bbbd Fix a possible use-after-free in custom_exts_free
This may happen when ssl_cert_dup calls custom_exts_copy, where
a possible memory allocation error causes custom_exts_free
to be called twice: once in the error handling of custom_exts_copy
and a second time in the error handling of ssl_cert_dup.

Reviewed-by: Matt Caswell <matt@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.org>
Reviewed-by: Richard Levitte <levitte@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/22772)
2023-11-22 09:34:55 +01:00
..
quic Correct tag len check when determining how much space we have in the pkt 2023-11-15 11:06:52 +01:00
record Make sure we remember how much data we sent in the event of a retry 2023-10-24 17:37:19 +01:00
statem Fix a possible use-after-free in custom_exts_free 2023-11-22 09:34:55 +01:00
bio_ssl.c Copyright year updates 2023-09-07 09:59:15 +01:00
build.info
d1_lib.c Move freeing of an old record layer to dtls1_clear_sent_buffer 2023-11-21 13:09:28 +01:00
d1_msg.c Copyright year updates 2023-09-07 09:59:15 +01:00
d1_srtp.c Copyright year updates 2023-09-07 09:59:15 +01:00
event_queue.c Remove a spurious inclusion of the sparse array header file 2023-09-25 07:45:32 +10:00
methods.c
pqueue.c
priority_queue.c Fix bug in priority queue remove function 2023-11-08 11:09:12 +00:00
s3_enc.c Copyright year updates 2023-09-07 09:59:15 +01:00
s3_lib.c Fix a possible memory leak of ssl->s3.tmp.psk 2023-11-09 17:33:55 +01:00
s3_msg.c
ssl_asn1.c
ssl_cert_comp.c Copyright year updates 2023-09-07 09:59:15 +01:00
ssl_cert_table.h Copyright year updates 2023-09-07 09:59:15 +01:00
ssl_cert.c
ssl_ciph.c Fix a possible memory leak in load_builtin_compressions 2023-11-02 08:17:08 +00:00
ssl_conf.c "foo * bar" should be "foo *bar" 2023-09-11 10:15:30 +02:00
ssl_err_legacy.c
ssl_err.c QUIC APL: Implement backpressure on stream creation 2023-08-25 15:10:43 +02:00
ssl_init.c Copyright year updates 2023-09-28 14:23:29 +01:00
ssl_lib.c Fix a possible memory leak in dane_tlsa_add 2023-11-22 09:18:21 +01:00
ssl_local.h Fix the SSL_CIPHER_find() function when used with a QCSO 2023-09-12 15:29:00 +02:00
ssl_mcnf.c
ssl_rsa_legacy.c
ssl_rsa.c Copyright year updates 2023-09-07 09:59:15 +01:00
ssl_sess.c
ssl_stat.c
ssl_txt.c
ssl_utst.c
sslerr.h
t1_enc.c Accept longer context for TLS 1.2 exporters 2023-10-26 15:47:15 +01:00
t1_lib.c
t1_trce.c
tls13_enc.c Copyright year updates 2023-09-07 09:59:15 +01:00
tls_depr.c
tls_srp.c