From b36272eac1b36982598c10de7af0a501582de07a Mon Sep 17 00:00:00 2001 From: Andreas Schneider Date: Tue, 11 Feb 2020 11:52:33 +0100 Subject: CVE-2020-1730: Fix a possible segfault when zeroing AES-CTR key Fixes T213 Signed-off-by: Andreas Schneider Reviewed-by: Anderson Toshiyuki Sasaki --- src/libcrypto.c | 8 ++++++-- 1 file changed, 6 insertions(+), 2 deletions(-) (limited to 'src') diff --git a/src/libcrypto.c b/src/libcrypto.c index b3792264..e9f519ec 100644 --- a/src/libcrypto.c +++ b/src/libcrypto.c @@ -713,8 +713,12 @@ aes_ctr_encrypt(struct ssh_cipher_struct *cipher, } static void aes_ctr_cleanup(struct ssh_cipher_struct *cipher){ - explicit_bzero(cipher->aes_key, sizeof(*cipher->aes_key)); - SAFE_FREE(cipher->aes_key); + if (cipher != NULL) { + if (cipher->aes_key != NULL) { + explicit_bzero(cipher->aes_key, sizeof(*cipher->aes_key)); + } + SAFE_FREE(cipher->aes_key); + } } #endif /* HAVE_OPENSSL_EVP_AES_CTR */ -- cgit v1.2.3