Commit afcee0e
committed
crypto: fix TLSWrap use-after-free on pending write
EncOut() passes pointers from the enc_out_ BIO internal buffer to the
underlying stream's uv_write(). write_size_ is non-zero while that
write is in flight. Calling ssl_.reset() frees the SSL context and
its BIOs, turning those pointers into dangling references. When libuv
completes the write it accesses freed memory (SIGSEGV).
Use ssl_.release() instead of ssl_.reset() when write_size_ != 0 so
the BIO data stays alive for the in-flight uv_write. This is a
bounded leak (one SSL context per socket destroyed with in-flight
writes) that prevents a segfault.
Also move RemoveStreamListener() before SSL cleanup so the underlying
stream cannot call back into the TLSWrap after its SSL state is gone.
Refs: #62393
Made-with: Cursor1 parent 0f68423 commit afcee0e
2 files changed
Lines changed: 71 additions & 6 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
1317 | 1317 | | |
1318 | 1318 | | |
1319 | 1319 | | |
1320 | | - | |
1321 | | - | |
1322 | | - | |
1323 | | - | |
1324 | | - | |
1325 | | - | |
| 1320 | + | |
1326 | 1321 | | |
1327 | 1322 | | |
1328 | 1323 | | |
| 1324 | + | |
| 1325 | + | |
| 1326 | + | |
| 1327 | + | |
| 1328 | + | |
| 1329 | + | |
| 1330 | + | |
| 1331 | + | |
| 1332 | + | |
| 1333 | + | |
| 1334 | + | |
| 1335 | + | |
| 1336 | + | |
| 1337 | + | |
1329 | 1338 | | |
1330 | 1339 | | |
1331 | 1340 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
| 1 | + | |
| 2 | + | |
| 3 | + | |
| 4 | + | |
| 5 | + | |
| 6 | + | |
| 7 | + | |
| 8 | + | |
| 9 | + | |
| 10 | + | |
| 11 | + | |
| 12 | + | |
| 13 | + | |
| 14 | + | |
| 15 | + | |
| 16 | + | |
| 17 | + | |
| 18 | + | |
| 19 | + | |
| 20 | + | |
| 21 | + | |
| 22 | + | |
| 23 | + | |
| 24 | + | |
| 25 | + | |
| 26 | + | |
| 27 | + | |
| 28 | + | |
| 29 | + | |
| 30 | + | |
| 31 | + | |
| 32 | + | |
| 33 | + | |
| 34 | + | |
| 35 | + | |
| 36 | + | |
| 37 | + | |
| 38 | + | |
| 39 | + | |
| 40 | + | |
| 41 | + | |
| 42 | + | |
| 43 | + | |
| 44 | + | |
| 45 | + | |
| 46 | + | |
| 47 | + | |
| 48 | + | |
| 49 | + | |
| 50 | + | |
| 51 | + | |
| 52 | + | |
| 53 | + | |
| 54 | + | |
| 55 | + | |
| 56 | + | |
0 commit comments