From: Matt Caswell Date: Wed, 12 Nov 2014 11:18:09 +0000 (+0000) Subject: Fix free of garbage pointer. PR#3595 X-Git-Tag: OpenSSL_1_0_2-pre-reformat~135 X-Git-Url: https://granicus.if.org/sourcecode?a=commitdiff_plain;h=5b3a5e3e901fe673749b14f3477cd5d16f40fd06;p=openssl Fix free of garbage pointer. PR#3595 Reviewed-by: Emilia Käsper (cherry picked from commit e04d426bf98ebb22abf0f15b6f09d333a6e8b2ad) --- diff --git a/crypto/ec/ec_mult.c b/crypto/ec/ec_mult.c index 19f21675fb..e81200b255 100644 --- a/crypto/ec/ec_mult.c +++ b/crypto/ec/ec_mult.c @@ -445,15 +445,16 @@ int ec_wNAF_mul(const EC_GROUP *group, EC_POINT *r, const BIGNUM *scalar, wNAF_len = OPENSSL_malloc(totalnum * sizeof wNAF_len[0]); wNAF = OPENSSL_malloc((totalnum + 1) * sizeof wNAF[0]); /* includes space for pivot */ val_sub = OPENSSL_malloc(totalnum * sizeof val_sub[0]); - + + /* Ensure wNAF is initialised in case we end up going to err */ + if (wNAF) wNAF[0] = NULL; /* preliminary pivot */ + if (!wsize || !wNAF_len || !wNAF || !val_sub) { ECerr(EC_F_EC_WNAF_MUL, ERR_R_MALLOC_FAILURE); goto err; } - wNAF[0] = NULL; /* preliminary pivot */ - /* num_val will be the total number of temporarily precomputed points */ num_val = 0;