Skip to content

Commit

Permalink
Check for uninitialised DRBG_CTX and don't free up default DRBG_CTX.
Browse files Browse the repository at this point in the history
  • Loading branch information
snhenson committed Oct 21, 2011
1 parent 3b59304 commit af4bfa1
Showing 1 changed file with 19 additions and 2 deletions.
21 changes: 19 additions & 2 deletions fips/rand/fips_drbg_lib.c
Original file line number Diff line number Diff line change
Expand Up @@ -135,8 +135,18 @@ void FIPS_drbg_free(DRBG_CTX *dctx)
{
if (dctx->uninstantiate)
dctx->uninstantiate(dctx);
OPENSSL_cleanse(&dctx->d, sizeof(dctx->d));
OPENSSL_free(dctx);
/* Don't free up default DRBG */
if (dctx == FIPS_get_default_drbg())
{
memset(dctx, 0, sizeof(DRBG_CTX));
dctx->type = 0;
dctx->status = DRBG_STATUS_UNINITIALISED;
}
else
{
OPENSSL_cleanse(&dctx->d, sizeof(dctx->d));
OPENSSL_free(dctx);
}
}

static size_t fips_get_entropy(DRBG_CTX *dctx, unsigned char **pout,
Expand Down Expand Up @@ -194,6 +204,7 @@ int FIPS_drbg_instantiate(DRBG_CTX *dctx,
FIPSerr(FIPS_F_FIPS_DRBG_INSTANTIATE, FIPS_R_ERROR_RETRIEVING_ENTROPY);
FIPSerr(FIPS_F_FIPS_DRBG_INSTANTIATE, FIPS_R_ERROR_RETRIEVING_NONCE);
FIPSerr(FIPS_F_FIPS_DRBG_INSTANTIATE, FIPS_R_INSTANTIATE_ERROR);
FIPSerr(FIPS_F_FIPS_DRBG_INSTANTIATE, FIPS_R_DRBG_NOT_INITIALISED);
#endif

int r = 0;
Expand All @@ -204,6 +215,12 @@ int FIPS_drbg_instantiate(DRBG_CTX *dctx,
goto end;
}

if (!dctx->instantiate)
{
r = FIPS_R_DRBG_NOT_INITIALISED;
goto end;
}

if (dctx->status != DRBG_STATUS_UNINITIALISED)
{
if (dctx->status == DRBG_STATUS_ERROR)
Expand Down

0 comments on commit af4bfa1

Please sign in to comment.