]> git.ipfire.org Git - thirdparty/openssl.git/commit
tls_process_cert_status_body(): Reject invalid cert status
authorRyan Hooper <ryhooper@cisco.com>
Thu, 13 Nov 2025 16:08:42 +0000 (11:08 -0500)
committerTomas Mraz <tomas@openssl.org>
Wed, 3 Dec 2025 16:23:45 +0000 (17:23 +0100)
commitccd8451428814ddbbed486f957a507b3cd7aa251
tree1b1764ddb7a606d430454c3a6bf57838ce6a790f
parent4e0dc7c91706d313a9cf9bd1972706a599933be1
tls_process_cert_status_body(): Reject invalid cert status

When a CertStatus message is received and the length of the
OCSP response is zero error out.

Reviewed-by: Matt Caswell <matt@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.org>
(Merged from https://github.com/openssl/openssl/pull/29207)
ssl/statem/statem_clnt.c