From a68236572850a1f50d5c40990b5a15a18ebea3bc Mon Sep 17 00:00:00 2001 From: Matt Caswell Date: Tue, 17 Apr 2018 11:32:20 +0100 Subject: [PATCH] Check the return from EVP_PKEY_get0_DH() Fixes #5934 Reviewed-by: Rich Salz (Merged from https://github.com/openssl/openssl/pull/5983) --- ssl/statem/statem_srvr.c | 6 ++++++ 1 file changed, 6 insertions(+) diff --git a/ssl/statem/statem_srvr.c b/ssl/statem/statem_srvr.c index 7e033ceb16..aa38fada70 100644 --- a/ssl/statem/statem_srvr.c +++ b/ssl/statem/statem_srvr.c @@ -2481,6 +2481,12 @@ int tls_construct_server_key_exchange(SSL *s, WPACKET *pkt) } dh = EVP_PKEY_get0_DH(s->s3->tmp.pkey); + if (dh == NULL) { + SSLfatal(s, SSL_AD_INTERNAL_ERROR, + SSL_F_TLS_CONSTRUCT_SERVER_KEY_EXCHANGE, + ERR_R_INTERNAL_ERROR); + goto err; + } EVP_PKEY_free(pkdh); pkdh = NULL; -- 2.40.0