Skip to content

Commit 9eb2a8a

Browse files
committed
Guard comparision when values are NULL
Fixes: CVE-2026-75805 Signed-off-by: Norbert Pocs <norbertp@openssl.org> Reviewed-by: Milan Broz <mbroz@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Tue Sep 29 11:04:17 2026
1 parent 469f3e4 commit 9eb2a8a

1 file changed

Lines changed: 11 additions & 4 deletions

File tree

‎crypto/cmp/cmp_client.c‎

Lines changed: 11 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -999,16 +999,23 @@ int OSSL_CMP_exec_RR_ses(OSSL_CMP_CTX *ctx)
999999
ret = 0;
10001000
goto err;
10011001
}
1002-
if (X509_NAME_cmp(issuer, OSSL_CRMF_CERTID_get0_issuer(cid)) != 0) {
1002+
/*
1003+
* The issuer and serial number are absent if the certificate to be
1004+
* revoked was given as a PKCS#10 CSR, in which case there is nothing
1005+
* to check the CertId of the response against.
1006+
*/
1007+
if (issuer != NULL
1008+
&& X509_NAME_cmp(issuer, OSSL_CRMF_CERTID_get0_issuer(cid)) != 0) {
10031009
#ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
10041010
ERR_raise(ERR_LIB_CMP, CMP_R_WRONG_CERTID_IN_RP);
10051011
ret = 0;
10061012
goto err;
10071013
#endif
10081014
}
1009-
if (ASN1_INTEGER_cmp(serial,
1010-
OSSL_CRMF_CERTID_get0_serialNumber(cid))
1011-
!= 0) {
1015+
if (serial != NULL
1016+
&& ASN1_INTEGER_cmp(serial,
1017+
OSSL_CRMF_CERTID_get0_serialNumber(cid))
1018+
!= 0) {
10121019
#ifndef FUZZING_BUILD_MODE_UNSAFE_FOR_PRODUCTION
10131020
ERR_raise(ERR_LIB_CMP, CMP_R_WRONG_SERIAL_IN_RP);
10141021
ret = 0;

0 commit comments

Comments
 (0)