Commit 669ca9b5ed for openssl.org

commit 669ca9b5ed5af2983564c931f47e92c54cce526c
Author: Norbert Pocs <norbertp@openssl.org>
Date:   Tue Sep 8 10:55:09 2026 +0200

    test: Check return value of SSL_CONNECTION_FROM_SSL

    This might return NULL and would cause dereference issue later.

    Resolves: https://scan5.scan.coverity.com/#/project-view/65248/10222?selectedIssue=1701001
    Complements: bfa50e13f857 "statem: test tls_construct_client_key_exchange"

    Signed-off-by: Norbert Pocs <norbertp@openssl.org>
    Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
    Reviewed-by: Milan Broz <mbroz@openssl.org>
    Merge-date: Thu Oct  1 08:09:30 2026
    Merged-from: https://github.com/openssl/openssl/pull/32737

diff --git a/test/statem_clnt_construct_test.c b/test/statem_clnt_construct_test.c
index da2fd39f88..5452676ba0 100644
--- a/test/statem_clnt_construct_test.c
+++ b/test/statem_clnt_construct_test.c
@@ -1081,6 +1081,9 @@ static int set_new_cipher(SSL *ssl, const char *name)
     STACK_OF(SSL_CIPHER) *ciphers = SSL_get_ciphers(ssl);
     int i;

+    if (s == NULL)
+        return 0;
+
     for (i = 0; i < sk_SSL_CIPHER_num(ciphers); i++) {
         const SSL_CIPHER *c = sk_SSL_CIPHER_value(ciphers, i);