From: Todd C. Miller Date: Mon, 24 Oct 2022 14:00:48 +0000 (-0600) Subject: ssl_cipher_process_rulestr: don't read outside rule_str buffer X-Git-Tag: openssl-3.2.0-alpha1~1835 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=428511ca66670e169a0e1b12e7540714b0be4cf8;p=thirdparty%2Fopenssl.git ssl_cipher_process_rulestr: don't read outside rule_str buffer If rule_str ended in a "-", "l" was incremented one byte past the end of the buffer. This resulted in an out-of-bounds read when "l" is dereferenced at the end of the loop. It is safest to just return early in this case since the condition occurs inside a nested loop. CLA: trivial Reviewed-by: Paul Dale Reviewed-by: Tomas Mraz (Merged from https://github.com/openssl/openssl/pull/19166) --- diff --git a/ssl/ssl_ciph.c b/ssl/ssl_ciph.c index 2ffad7008cb..48aad6342bd 100644 --- a/ssl/ssl_ciph.c +++ b/ssl/ssl_ciph.c @@ -1062,9 +1062,7 @@ static int ssl_cipher_process_rulestr(const char *rule_str, * alphanumeric, so we call this an error. */ ERR_raise(ERR_LIB_SSL, SSL_R_INVALID_COMMAND); - retval = found = 0; - l++; - break; + return 0; } if (rule == CIPHER_SPECIAL) {