From: Ingo Franzki Date: Wed, 30 Aug 2023 06:41:43 +0000 (+0200) Subject: OPENSSL_init_crypto load config into initial global default library context X-Git-Tag: openssl-3.2.0-alpha1~105 X-Git-Url: http://git.ipfire.org/?a=commitdiff_plain;h=ecb6cdf02a302af18fe4bc20097a9ea3177f897c;p=thirdparty%2Fopenssl.git OPENSSL_init_crypto load config into initial global default library context OPENSSL_init_crypto() with OPENSSL_INIT_LOAD_CONFIG must load the configuration into the initial global default library context, not the currently set default library context. OPENSSL_init_crypto() with OPENSSL_INIT_LOAD_CONFIG may be called within other OpenSSL API functions, e.g. from within EVP_PKEY_CTX_new_xxx() when initializing a pkey context, to perform implicit initialization, if it has not been initialized yet. This implicit initialization may happen at a time when an application has already create its own library context and made it the default library context. So loading the config into the current default library context would load it into the applications library context. Signed-off-by: Ingo Franzki Reviewed-by: Dmitry Belyavskiy Reviewed-by: Matt Caswell Reviewed-by: Tomas Mraz (Merged from https://github.com/openssl/openssl/pull/21897) --- diff --git a/crypto/conf/conf_sap.c b/crypto/conf/conf_sap.c index be87aaf7e82..2e184886641 100644 --- a/crypto/conf/conf_sap.c +++ b/crypto/conf/conf_sap.c @@ -65,7 +65,8 @@ int ossl_config_int(const OPENSSL_INIT_SETTINGS *settings) #endif #ifndef OPENSSL_SYS_UEFI - ret = CONF_modules_load_file(filename, appname, flags); + ret = CONF_modules_load_file_ex(OSSL_LIB_CTX_get0_global_default(), + filename, appname, flags); #else ret = 1; #endif