aboutsummaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorNick Mathewson <nickm@torproject.org>2017-02-07 08:55:07 -0500
committerNick Mathewson <nickm@torproject.org>2017-02-07 08:55:07 -0500
commit115cefdeeefd99f435948bfe42b1ce842019edfb (patch)
tree06b41270631e38e894fee7a8fb98da69317fca7f
parenteb72365554451f5e129169bb1216a9610f7ff183 (diff)
parente6965f78b80e2b83367df05e204c97f5c0929a3c (diff)
downloadtor-115cefdeeefd99f435948bfe42b1ce842019edfb.tar.gz
tor-115cefdeeefd99f435948bfe42b1ce842019edfb.zip
Merge branch 'maint-0.2.6' into maint-0.2.7
-rw-r--r--changes/rsa_init_bug7
-rw-r--r--src/common/crypto.c4
2 files changed, 10 insertions, 1 deletions
diff --git a/changes/rsa_init_bug b/changes/rsa_init_bug
new file mode 100644
index 0000000000..6b5fb4f2f9
--- /dev/null
+++ b/changes/rsa_init_bug
@@ -0,0 +1,7 @@
+ o Major bugfixes (key management):
+ - If OpenSSL fails to generate an RSA key, do not retain a dangling pointer
+ to the previous (uninitialized) key value. The impact here should be
+ limited to a difficult-to-trigger crash, if OpenSSL is running an
+ engine that makes key generation failures possible, or if OpenSSL runs
+ out of memory. Fixes bug 19152; bugfix on 0.2.1.10-alpha. Found by
+ Yuan Jochen Kang, Suman Jana, and Baishakhi Ray.
diff --git a/src/common/crypto.c b/src/common/crypto.c
index 57981f9a00..a45f46d8f2 100644
--- a/src/common/crypto.c
+++ b/src/common/crypto.c
@@ -558,8 +558,10 @@ crypto_pk_generate_key_with_bits(crypto_pk_t *env, int bits)
{
tor_assert(env);
- if (env->key)
+ if (env->key) {
RSA_free(env->key);
+ env->key = NULL;
+ }
{
BIGNUM *e = BN_new();