From: Dr. Matthias St. Pierre Date: Wed, 6 May 2020 15:24:13 +0000 (+0200) Subject: Fix use-after-free in BIO_C_SET_SSL callback X-Git-Tag: openssl-3.0.0-alpha2~61 X-Git-Url: https://git.librecmc.org/?a=commitdiff_plain;h=73d6b4efe6835a6c97ce61df6bf339b0903e5b7a;p=oweals%2Fopenssl.git Fix use-after-free in BIO_C_SET_SSL callback Since the BIO_SSL structure was renewed by `ssl_free(b)/ssl_new(b)`, the `bs` pointer needs to be updated before assigning to `bs->ssl`. Thanks to @suishixingkong for reporting the issue and providing a fix. Closes #10539 Reviewed-by: Tomas Mraz (Merged from https://github.com/openssl/openssl/pull/11746) --- diff --git a/ssl/bio_ssl.c b/ssl/bio_ssl.c index b44ec3e5e1..ca364fd14f 100644 --- a/ssl/bio_ssl.c +++ b/ssl/bio_ssl.c @@ -284,6 +284,7 @@ static long ssl_ctrl(BIO *b, int cmd, long num, void *ptr) ssl_free(b); if (!ssl_new(b)) return 0; + bs = BIO_get_data(b); } BIO_set_shutdown(b, num); ssl = (SSL *)ptr;