Skip to content

Commit ab52d88

Browse files
igus68t8m
authored andcommitted
Fix potential NULL dereference processing CMS PasswordRecipientInfo
Avoid NULL dereferencing when keyDerivationAlgorithm is absent in CMS PasswordRecipientInfo. Fixes CVE-2026-42766 Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> MergeDate: Mon Jun 8 18:57:52 2026 (cherry picked from commit f019b72c589071a73acda9812775389a857884c9)
1 parent d2e9efb commit ab52d88

1 file changed

Lines changed: 5 additions & 0 deletions

File tree

‎crypto/cms/cms_pwri.c‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -367,6 +367,11 @@ int ossl_cms_RecipientInfo_pwri_crypt(const CMS_ContentInfo *cms,
367367

368368
/* Finish password based key derivation to setup key in "ctx" */
369369

370+
if (algtmp == NULL) {
371+
ERR_raise_data(ERR_LIB_CMS, CMS_R_INVALID_KEY_ENCRYPTION_PARAMETER,
372+
"Missing KeyDerivationAlgorithm");
373+
goto err;
374+
}
370375
if (!EVP_PBE_CipherInit_ex(algtmp->algorithm,
371376
(char *)pwri->pass, (int)pwri->passlen,
372377
algtmp->parameter, kekctx, en_de,

0 commit comments

Comments
 (0)