Commit e65f680e26 for openssl.org
commit e65f680e265f630d43e83a1313d71297df2d7832
Author: Eugene Syromiatnikov <esyr@openssl.org>
Date: Mon Sep 21 09:47:47 2026 +0200
ssl/statem/statem_srvr.c: drop needless s->d1 NULL check
Remove a needless s->d1 check for NULL
in tls_early_post_process_client_hello(), as it is under
SSL_CONNECTION_IS_DTLS(s).
Reported by Coverity as dereference of potential NULL s->d1 pointer
when using s->d1->cookie_len, CID 1700558.
Resolves: https://scan5.scan.coverity.com/#/project-view/65248/10222?selectedIssue=1700558
Complements: 2f0ad0d852ea "DTLS 1.3 Limit DTLSv1_listen to DTLS1.2 and add SSL Listener for DTLS"
Signed-off-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Norbert Pocs <norbertp@openssl.org>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Merge-date: Tue Sep 29 16:43:45 2026
Merged-from: https://github.com/openssl/openssl/pull/32900
diff --git a/ssl/statem/statem_srvr.c b/ssl/statem/statem_srvr.c
index 8f1def3c9f..75dc8d5f50 100644
--- a/ssl/statem/statem_srvr.c
+++ b/ssl/statem/statem_srvr.c
@@ -2134,9 +2134,7 @@ static int tls_early_post_process_client_hello(SSL_CONNECTION *s)
int verify_ret = 0;
#if !defined(OPENSSL_NO_DTLS)
- DTLS_LISTENER *dl = (s->d1 != NULL && s->d1->listener != NULL)
- ? (DTLS_LISTENER *)s->d1->listener
- : NULL;
+ DTLS_LISTENER *dl = (DTLS_LISTENER *)s->d1->listener;
if (dl != NULL && dl->require_hvr_cookie && sctx->app_verify_cookie_cb == NULL) {
verify_ret = ossl_dtls_listener_verify_cookie_cb(ussl,