Fix the array size of dtlsseq in tls1_enc
authorBernd Edlinger <bernd.edlinger@hotmail.de>
Mon, 23 Aug 2021 12:03:20 +0000 (14:03 +0200)
committerTomas Mraz <tomas@openssl.org>
Wed, 25 Aug 2021 14:53:24 +0000 (16:53 +0200)
Reviewed-by: Tomas Mraz <tomas@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/16385)

ssl/record/ssl3_record.c

index 30af6508a75cb23e3893561b155ffa49a91797c2..b6ac61e0e8084fd82b4081d27efb1a6f5acaa457 100644 (file)
@@ -1047,7 +1047,7 @@ int tls1_enc(SSL *s, SSL3_RECORD *recs, size_t n_recs, int sending,
 
                 if (SSL_IS_DTLS(s)) {
                     /* DTLS does not support pipelining */
-                    unsigned char dtlsseq[9], *p = dtlsseq;
+                    unsigned char dtlsseq[8], *p = dtlsseq;
 
                     s2n(sending ? DTLS_RECORD_LAYER_get_w_epoch(&s->rlayer) :
                         DTLS_RECORD_LAYER_get_r_epoch(&s->rlayer), p);