x509v3/v3_utl.c: avoid double-free.
authorAndy Polyakov <appro@openssl.org>
Sat, 14 Oct 2017 08:21:19 +0000 (10:21 +0200)
committerAndy Polyakov <appro@openssl.org>
Fri, 27 Oct 2017 09:26:12 +0000 (11:26 +0200)
Thanks to David Benjamin for spotting this.

Reviewed-by: Rich Salz <rsalz@openssl.org>
Reviewed-by: Richard Levitte <levitte@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/4532)

(cherry picked from commit 432f8688bb72e21939845ac7a69359ca718c6676)

Reviewed-by: Rich Salz <rsalz@openssl.org>
Reviewed-by: Richard Levitte <levitte@openssl.org>
Reviewed-by: Bernd Edlinger <bernd.edlinger@hotmail.de>
(Merged from https://github.com/openssl/openssl/pull/4514)

crypto/x509v3/v3_utl.c

index adc1552490e2922be941fed6b929d77690a1ee7f..d9cc7c7cd617739d781563e880042a138b7633bf 100644 (file)
@@ -55,8 +55,10 @@ int X509V3_add_value(const char *name, const char *value,
     return 1;
  err:
     X509V3err(X509V3_F_X509V3_ADD_VALUE, ERR_R_MALLOC_FAILURE);
-    if (sk_allocated)
+    if (sk_allocated) {
         sk_CONF_VALUE_free(*extlist);
+        *extlist = NULL;
+    }
     OPENSSL_free(vtmp);
     OPENSSL_free(tname);
     OPENSSL_free(tvalue);