Edit

IABSD.fr/src/sbin

Branch :

  • Show log

    Commit

  • Author : hshoexer
    Date : 2026-05-26 11:17:14
    Hash : 3c9734eb
    Message : iked: Avoid NULL-deref in ocsp_connect_finish() Several error path in ocsp_connect() can call ocsp_connect_finish() with oc == NULL. This will result in a NULL-deref. To recover gracefully the child requesting the OCSP file descriptor needs to be notified, otherwise the stale request will exist in the child forever. To accomplish this, provide struct iked_sahdr *sh directly to ocsp_connect_finish() as a parameter. So sh is guaranteed to be valid even when oc is NULL. While there, avoid a potential double-free on oc_path when a strdup(3) fails. ok tobhe@