Commit 0bea175
committed
fix: use proper return value check for EVP_CIPHER_CTX_ctrl()
This function can theoretically return -1, which would then be converted
to a truthy value. If this happens, then this can cause issues at the
use sites. E.g. for the test-crypto-cipheriv-decipheriv test in Node
this can cause a buffer overflow when we test with an injected error:
```
==714700==ERROR: AddressSanitizer: heap-buffer-overflow on address 0x502000032b98
READ of size 12 at 0x502000032b98 thread T0
#0 0x558a7790bb97 in memcpy (/work/node/out/Debug/node+0x1b0bb97)
#1 0x7efe5386f90b (/lib/x86_64-linux-gnu/libcrypto.so.3+0x45f90b)
#2 0x7efe536312c2 in EVP_CipherInit_ex (/lib/x86_64-linux-gnu/libcrypto.so.3+0x2212c2)
#3 0x558a7d3e7785 in ncrypto::CipherCtxPointer::init
/work/node/out/../deps/ncrypto/ncrypto.cc:3328:10
#4 0x558a78512a1b in node::crypto::CipherBase::CommonInit
/work/node/out/../src/crypto/crypto_cipher.cc:366:13
#5 0x558a785125dd in node::crypto::CipherBase::InitIv
/work/node/out/../src/crypto/crypto_cipher.cc:409:3
#6 0x558a7850f5f4 in node::crypto::CipherBase::New
/work/node/out/../src/crypto/crypto_cipher.cc:328:11
#7 0x558a788ee605 in v8::internal::FunctionCallbackArguments::CallOrConstruct
/work/node/out/../deps/v8/src/api/api-arguments-inl.h:93:3
#8 0x558a788ec3ba in v8::internal::MaybeHandle<v8::internal::Object>
v8::internal::(anonymous namespace)::HandleApiCallHelper<true>
/work/node/out/../deps/v8/src/builtins/builtins-api.cc:104:16
#9 0x558a788e91fc in v8::internal::Builtin_Impl_HandleApiConstruct
/work/node/out/../deps/v8/src/builtins/builtins-api.cc:135:3
#10 0x558a788e91fc in v8::internal::Builtin_HandleApiConstruct
/work/node/out/../deps/v8/src/builtins/builtins-api.cc:126:1
#11 0x7efe31a951b5 (<unknown module>)
```1 parent 630ee8b commit 0bea175
1 file changed
Lines changed: 7 additions & 5 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
3403 | 3403 | | |
3404 | 3404 | | |
3405 | 3405 | | |
3406 | | - | |
| 3406 | + | |
3407 | 3407 | | |
3408 | 3408 | | |
3409 | 3409 | | |
3410 | 3410 | | |
3411 | | - | |
3412 | | - | |
| 3411 | + | |
| 3412 | + | |
| 3413 | + | |
| 3414 | + | |
3413 | 3415 | | |
3414 | 3416 | | |
3415 | 3417 | | |
3416 | 3418 | | |
3417 | 3419 | | |
3418 | | - | |
| 3420 | + | |
3419 | 3421 | | |
3420 | 3422 | | |
3421 | 3423 | | |
| |||
3485 | 3487 | | |
3486 | 3488 | | |
3487 | 3489 | | |
3488 | | - | |
| 3490 | + | |
3489 | 3491 | | |
3490 | 3492 | | |
3491 | 3493 | | |
| |||
0 commit comments