From df8222fb189708199a185f73543b6e0602c1c72f Mon Sep 17 00:00:00 2001 From: Petr Mensik Date: Tue, 20 Sep 2022 11:21:45 +0200 Subject: [PATCH 3/4] Fix CVE-2022-38177 5961. [security] Fix memory leak in ECDSA verify processing. (CVE-2022-38177) [GL #3487] --- lib/dns/opensslecdsa_link.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/lib/dns/opensslecdsa_link.c b/lib/dns/opensslecdsa_link.c index ce4c8c4..3847896 100644 --- a/lib/dns/opensslecdsa_link.c +++ b/lib/dns/opensslecdsa_link.c @@ -228,7 +228,7 @@ opensslecdsa_verify(dst_context_t *dctx, const isc_region_t *sig) { } if (sig->length != siglen) { - return (DST_R_VERIFYFAILURE); + DST_RET(DST_R_VERIFYFAILURE); } if (!EVP_DigestFinal_ex(evp_md_ctx, digest, &dgstlen)) { -- 2.37.3