]> git.ipfire.org Git - thirdparty/openssl.git/commit
apps/ocsp.c: avoid using NULL resp
authorEugene Syromiatnikov <esyr@openssl.org>
Mon, 1 Sep 2025 14:42:15 +0000 (16:42 +0200)
committerNeil Horman <nhorman@openssl.org>
Mon, 8 Sep 2025 20:56:58 +0000 (16:56 -0400)
commit6dd7ae2f4103b368cd6b66a053b7a9323c9fb9ad
tree10ed8b00041b2c7cb9e4fc980724867736e6a2a9
parent58f1782b20654390836e991c538d7b5f80035daf
apps/ocsp.c: avoid using NULL resp

There are some code paths where resp is used without a previous check
for being non-NULL (specifically, OCSP_response_create() can return
NULL, and do_responder() can return -1, that would also lead to resp
being NULL).  Avoid hitting NULL dereferences by wrapping the code that
uses resp in "if (resp != NULL)".

Resolves: https://scan5.scan.coverity.com/#/project-view/65248/10222?selectedIssue=1665155
References: https://github.com/openssl/project/issues/1362
Signed-off-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.org>
Reviewed-by: Paul Dale <ppzgs1@gmail.com>
Reviewed-by: Neil Horman <nhorman@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/28407)
apps/ocsp.c