bbd2dd
diff -up openssl-1.0.2k/crypto/dh/dh_key.c.large-dh openssl-1.0.2k/crypto/dh/dh_key.c
bbd2dd
--- openssl-1.0.2k/crypto/dh/dh_key.c.large-dh	2018-06-18 13:46:24.268137362 +0200
bbd2dd
+++ openssl-1.0.2k/crypto/dh/dh_key.c	2018-06-18 13:59:04.605497462 +0200
bbd2dd
@@ -133,7 +133,7 @@ static int generate_key(DH *dh)
bbd2dd
     int ok = 0;
bbd2dd
     int generate_new_key = 0;
bbd2dd
     unsigned l;
bbd2dd
-    BN_CTX *ctx;
bbd2dd
+    BN_CTX *ctx = NULL;
bbd2dd
     BN_MONT_CTX *mont = NULL;
bbd2dd
     BIGNUM *pub_key = NULL, *priv_key = NULL;
bbd2dd
 
bbd2dd
@@ -145,6 +145,11 @@ static int generate_key(DH *dh)
bbd2dd
     }
bbd2dd
 #endif
bbd2dd
 
bbd2dd
+    if (BN_num_bits(dh->p) > OPENSSL_DH_MAX_MODULUS_BITS) {
bbd2dd
+        DHerr(DH_F_GENERATE_KEY, DH_R_MODULUS_TOO_LARGE);
bbd2dd
+        return 0;
bbd2dd
+    }
bbd2dd
+
bbd2dd
     ctx = BN_CTX_new();
bbd2dd
     if (ctx == NULL)
bbd2dd
         goto err;