From 0c49ec97f4f4e9e82da19ce694249c2e78de6d88 Mon Sep 17 00:00:00 2001 From: David Benjamin Date: Sat, 12 Jul 2014 13:16:51 -0400 Subject: [PATCH] Fix potential memory leak. This can't happen because we don't implement RSA_PSK, but we probably should check here. Probably |sess_cert| shouldn't be attached to SSL_SESSION anyway; it's only relevant when initializing the session and if it's accessed afterwards, it'll be shared and cause problems. Change-Id: Id868e523195f33c22e057f9b89dc02fe68e9b554 Reviewed-on: https://boringssl-review.googlesource.com/1153 Reviewed-by: Adam Langley --- ssl/s3_clnt.c | 6 +++++- 1 file changed, 5 insertions(+), 1 deletion(-) diff --git a/ssl/s3_clnt.c b/ssl/s3_clnt.c index 246539cf7..f7cc48874 100644 --- a/ssl/s3_clnt.c +++ b/ssl/s3_clnt.c @@ -1335,7 +1335,11 @@ int ssl3_get_key_exchange(SSL *s) later.*/ if (s->s3->tmp.new_cipher->algorithm_auth & SSL_aPSK) { - s->session->sess_cert=ssl_sess_cert_new(); + /* PSK ciphersuites that also send a + * Certificate would have already initialized + * |sess_cert|. */ + if (s->session->sess_cert == NULL) + s->session->sess_cert = ssl_sess_cert_new(); if (s->session->psk_identity_hint) { OPENSSL_free(s->session->psk_identity_hint);