Commit 6f71d7da authored by Matt Caswell's avatar Matt Caswell
Browse files

When using EVP_PKEY_derive with a KDF set, a negative error from


ECDH_compute_key is silently ignored and the KDF is run on duff data

Thanks to github user tomykaira for the suggested fix.

Reviewed-by: default avatarDr. Stephen Henson <steve@openssl.org>
(cherry picked from commit 8d02bebd)
parent 0b9e8276
Loading
Loading
Loading
Loading
+2 −2
Original line number Diff line number Diff line
@@ -244,8 +244,8 @@ static int pkey_ec_derive(EVP_PKEY_CTX *ctx, unsigned char *key, size_t *keylen)
	outlen = *keylen;
		
	ret = ECDH_compute_key(key, outlen, pubkey, eckey, 0);
	if (ret < 0)
		return ret;
	if (ret <= 0)
		return 0;
	*keylen = ret;
	return 1;
	}