Skip to content

Commit b90ff3b

Browse files
igus68t8m
authored andcommitted
Fix potential NULL dereference in OSSL_CRMF_ENCRYPTEDVALUE_decrypt()
Check that 'parameter' != NULL before dereferencing in OSSL_CRMF_ENCRYPTEDVALUE_decrypt(). Fixes CVE-2026-42767 Reviewed-by: Neil Horman <nhorman@openssl.org> Reviewed-by: Norbert Pocs <norbertp@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> MergeDate: Mon Jun 8 20:38:27 2026 (cherry picked from commit 309db711d13a6fdc6f8a719d8b4415a04dbf3bc5)
1 parent 370124c commit b90ff3b

1 file changed

Lines changed: 6 additions & 4 deletions

File tree

‎crypto/crmf/crmf_lib.c‎

Lines changed: 6 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -762,6 +762,7 @@ unsigned char *OSSL_CRMF_ENCRYPTEDVALUE_decrypt(const OSSL_CRMF_ENCRYPTEDVALUE *
762762
EVP_CIPHER *cipher = NULL; /* used cipher */
763763
int cikeysize = 0; /* key size from cipher */
764764
unsigned char *iv = NULL; /* initial vector for symmetric encryption */
765+
int iv_len; /* iv length */
765766
unsigned char *out = NULL; /* decryption output buffer */
766767
int n, ret = 0;
767768
EVP_PKEY_CTX *pkctx = NULL; /* private key context */
@@ -811,11 +812,12 @@ unsigned char *OSSL_CRMF_ENCRYPTEDVALUE_decrypt(const OSSL_CRMF_ENCRYPTEDVALUE *
811812
} else {
812813
goto end;
813814
}
814-
if ((iv = OPENSSL_malloc(EVP_CIPHER_get_iv_length(cipher))) == NULL)
815+
iv_len = EVP_CIPHER_get_iv_length(cipher);
816+
if ((iv = OPENSSL_malloc(iv_len)) == NULL)
815817
goto end;
816-
if (ASN1_TYPE_get_octetstring(enc->symmAlg->parameter, iv,
817-
EVP_CIPHER_get_iv_length(cipher))
818-
!= EVP_CIPHER_get_iv_length(cipher)) {
818+
if (enc->symmAlg->parameter == NULL
819+
|| ASN1_TYPE_get_octetstring(enc->symmAlg->parameter, iv, iv_len)
820+
!= iv_len) {
819821
ERR_raise(ERR_LIB_CRMF, CRMF_R_MALFORMED_IV);
820822
goto end;
821823
}

0 commit comments

Comments
 (0)