summaryrefslogtreecommitdiff
path: root/lib
diff options
context:
space:
mode:
authorMiod Vallat <miod@cvs.openbsd.org>2014-05-18 16:13:49 +0000
committerMiod Vallat <miod@cvs.openbsd.org>2014-05-18 16:13:49 +0000
commit7e6b90433a7edba1b5c0bb26de6b40e7d1ecb770 (patch)
treec98901c34415f4d5183c6a8402b4f0ba04fde07a /lib
parenta71ebc8d6d8ed6ccde26b10d0d6b33d52abbd888 (diff)
In dtls1_reassemble_fragment() and dtls1_process_out_of_seq_message(), in case
of error, make sure we do not free pitem which is still linked into the pqueue. In the same vain, only free `frag' if we allocated it in this function. Help and ok beck@
Diffstat (limited to 'lib')
-rw-r--r--lib/libssl/d1_both.c10
1 files changed, 3 insertions, 7 deletions
diff --git a/lib/libssl/d1_both.c b/lib/libssl/d1_both.c
index db57bf9d3d5..10b62cd4104 100644
--- a/lib/libssl/d1_both.c
+++ b/lib/libssl/d1_both.c
@@ -618,7 +618,7 @@ dtls1_reassemble_fragment(SSL *s, struct hm_header_st* msg_hdr, int *ok)
frag->msg_header.frag_len = frag->msg_header.msg_len;
frag->msg_header.frag_off = 0;
} else
- frag = (hm_fragment*) item->data;
+ frag = (hm_fragment*)item->data;
/* If message is already reassembled, this must be a
* retransmit and can be dropped.
@@ -671,10 +671,8 @@ dtls1_reassemble_fragment(SSL *s, struct hm_header_st* msg_hdr, int *ok)
return DTLS1_HM_FRAGMENT_RETRY;
err:
- if (frag != NULL)
+ if (item == NULL && frag != NULL)
dtls1_hm_fragment_free(frag);
- if (item != NULL)
- free(item);
*ok = 0;
return i;
}
@@ -755,10 +753,8 @@ dtls1_process_out_of_seq_message(SSL *s, struct hm_header_st* msg_hdr, int *ok)
return DTLS1_HM_FRAGMENT_RETRY;
err:
- if (frag != NULL)
+ if (item == NULL && frag != NULL)
dtls1_hm_fragment_free(frag);
- if (item != NULL)
- free(item);
*ok = 0;
return i;
}