Skip to content

Commit 131145d

Browse files
n13lt8m
authored andcommitted
Fix Double-free When Checking OCSP Stapled Response
If OCSP stapling is enabled and the TLS client connects to a malicious server, a crafted OCSP stapled response can trigger a double free in the TLS client when the stapled response is checked. The OCSP stapling is not enabled by default. Reliable code execution through a double-free is technically complex and highly environment-dependent but the Denial of Service impact is straightforward to achieve, warranting Moderate severity. Fixes CVE-2026-35188 Reviewed-by: Neil Horman <nhorman@openssl.org> Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> MergeDate: Mon Jun 8 14:44:58 2026 (cherry picked from commit ac4b7adc4e8208b27a12b2e345b067ca49e3c451)
1 parent 391d6bc commit 131145d

1 file changed

Lines changed: 1 addition & 0 deletions

File tree

‎crypto/x509/x509_vfy.c‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1188,6 +1188,7 @@ static int check_cert_ocsp_resp(X509_STORE_CTX *ctx)
11881188

11891189
if (OCSP_response_status(resp) != OCSP_RESPONSE_STATUS_SUCCESSFUL) {
11901190
OCSP_BASICRESP_free(bs);
1191+
bs = NULL;
11911192
ret = X509_V_ERR_OCSP_RESP_INVALID;
11921193
goto end;
11931194
}

0 commit comments

Comments
 (0)