Skip to content

Commit

Permalink
openssl/verify_sha: Fix double free on EC sigs
Browse files Browse the repository at this point in the history
Signed-off-by: Ben Collins <[email protected]>
  • Loading branch information
benmcollins committed Feb 13, 2025
1 parent d0d464e commit 2ea11b1
Showing 1 changed file with 3 additions and 3 deletions.
6 changes: 3 additions & 3 deletions libjwt/openssl/sign-verify.c
Original file line number Diff line number Diff line change
Expand Up @@ -283,7 +283,7 @@ static int openssl_verify_sha_pem(jwt_t *jwt, const char *head,

if (!ops_compat(jwt->key, JWT_CRYPTO_OPS_OPENSSL))
VERIFY_ERROR("Key is not compatible"); // LCOV_EXCL_LINE

pkey = jwt->key->provider_data;

switch (jwt->alg) {
Expand Down Expand Up @@ -373,8 +373,8 @@ static int openssl_verify_sha_pem(jwt_t *jwt, const char *head,

slen = i2d_ECDSA_SIG(ec_sig, NULL);

/* Reset this with the new information. */
sig = jwt_realloc(sig, slen);
/* Reset this with the new information */
sig = jwt_malloc(slen);
if (sig == NULL)
VERIFY_ERROR("Out of memory"); // LCOV_EXCL_LINE

Expand Down

0 comments on commit 2ea11b1

Please sign in to comment.