From 8957adda165f77589090627d6563796331c0c94b Mon Sep 17 00:00:00 2001 From: Bernd Edlinger Date: Thu, 22 Dec 2016 13:51:27 +0100 Subject: Fix error handling in compute_key, BN_CTX_get can return NULL Reviewed-by: Rich Salz Reviewed-by: Richard Levitte (Merged from https://github.com/openssl/openssl/pull/2132) (cherry picked from commit 7928ee4d685b727619555bc1ec0aee805f6fc8c4) --- crypto/dh/dh_key.c | 2 ++ 1 file changed, 2 insertions(+) (limited to 'crypto') diff --git a/crypto/dh/dh_key.c b/crypto/dh/dh_key.c index 1d80fb2c5f..387558f146 100644 --- a/crypto/dh/dh_key.c +++ b/crypto/dh/dh_key.c @@ -223,6 +223,8 @@ static int compute_key(unsigned char *key, const BIGNUM *pub_key, DH *dh) goto err; BN_CTX_start(ctx); tmp = BN_CTX_get(ctx); + if (tmp == NULL) + goto err; if (dh->priv_key == NULL) { DHerr(DH_F_COMPUTE_KEY, DH_R_NO_PRIVATE_VALUE); -- cgit v1.2.3