Check the return from EVP_PKEY_get0_DH()
authorMatt Caswell <matt@openssl.org>
Tue, 17 Apr 2018 10:32:20 +0000 (11:32 +0100)
committerMatt Caswell <matt@openssl.org>
Tue, 17 Apr 2018 16:09:09 +0000 (17:09 +0100)
Fixes #5934

Reviewed-by: Rich Salz <rsalz@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/5983)

ssl/statem/statem_srvr.c

index 7e033ce..aa38fad 100644 (file)
@@ -2481,6 +2481,12 @@ int tls_construct_server_key_exchange(SSL *s, WPACKET *pkt)
         }
 
         dh = EVP_PKEY_get0_DH(s->s3->tmp.pkey);
+        if (dh == NULL) {
+            SSLfatal(s, SSL_AD_INTERNAL_ERROR,
+                     SSL_F_TLS_CONSTRUCT_SERVER_KEY_EXCHANGE,
+                     ERR_R_INTERNAL_ERROR);
+            goto err;
+        }
 
         EVP_PKEY_free(pkdh);
         pkdh = NULL;