From 294189c6a84d22db437501a631394b2ded5bac99 Mon Sep 17 00:00:00 2001 From: Damien Miller Date: Tue, 13 Oct 2015 00:21:28 +0000 Subject: free the correct IV length, don't assume it's always the cipher blocksize; ok dtucker@ --- usr.bin/ssh/kex.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/usr.bin/ssh/kex.c b/usr.bin/ssh/kex.c index 05628732f96..111a3e52f48 100644 --- a/usr.bin/ssh/kex.c +++ b/usr.bin/ssh/kex.c @@ -1,4 +1,4 @@ -/* $OpenBSD: kex.c,v 1.110 2015/08/21 23:57:48 djm Exp $ */ +/* $OpenBSD: kex.c,v 1.111 2015/10/13 00:21:27 djm Exp $ */ /* * Copyright (c) 2000, 2001 Markus Friedl. All rights reserved. * @@ -462,7 +462,7 @@ kex_free_newkeys(struct newkeys *newkeys) newkeys->enc.key = NULL; } if (newkeys->enc.iv) { - explicit_bzero(newkeys->enc.iv, newkeys->enc.block_size); + explicit_bzero(newkeys->enc.iv, newkeys->enc.iv_len); free(newkeys->enc.iv); newkeys->enc.iv = NULL; } -- cgit v1.2.3