Commit 680cc06066 for openssl.org

commit 680cc06066601d541e99604718806eb6cb601c0d
Author: mzfr <github@mzfr.in>
Date:   Wed Sep 23 19:26:17 2026 +0800

    srtpkdf: avoid NULL dereference in size queries

    Return an error when the cipher has not been configured instead of
    passing NULL to EVP_CIPHER_get_key_length(). Add regression coverage
    for fresh, configured, and reset contexts.

    Fixes #32945

    Reviewed-by: Paul Dale <paul.dale@oracle.com>
    Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
    Merge-date: Fri Oct  2 08:12:15 2026
    Merged-from: https://github.com/openssl/openssl/pull/32959

diff --git a/providers/implementations/kdfs/srtpkdf.c b/providers/implementations/kdfs/srtpkdf.c
index 4ae77aedee..e55a404257 100644
--- a/providers/implementations/kdfs/srtpkdf.c
+++ b/providers/implementations/kdfs/srtpkdf.c
@@ -303,7 +303,12 @@ static int kdf_srtpkdf_get_ctx_params(void *vctx, OSSL_PARAM params[])
         return 0;

     if (p.size != NULL) {
-        size_t sz = EVP_CIPHER_key_length(ossl_prov_cipher_cipher(&ctx->cipher));
+        const EVP_CIPHER *cipher = ossl_prov_cipher_cipher(&ctx->cipher);
+        size_t sz;
+
+        if (cipher == NULL)
+            return 0;
+        sz = EVP_CIPHER_key_length(cipher);

         if (!OSSL_PARAM_set_size_t(p.size, sz))
             return 0;
diff --git a/test/evp_kdf_test.c b/test/evp_kdf_test.c
index 6d4a55d11e..01e2726b71 100644
--- a/test/evp_kdf_test.c
+++ b/test/evp_kdf_test.c
@@ -1988,6 +1988,35 @@ static int test_kdf_ss_kmac(void)
 }
 #endif /* OPENSSL_NO_SSKDF */

+#ifndef OPENSSL_NO_SRTPKDF
+static int test_kdf_srtpkdf_size(void)
+{
+    int ret = 0;
+    size_t size = 0;
+    EVP_KDF_CTX *kctx = NULL;
+    OSSL_PARAM get_params[2], set_params[2];
+
+    get_params[0] = OSSL_PARAM_construct_size_t(OSSL_KDF_PARAM_SIZE, &size);
+    get_params[1] = OSSL_PARAM_construct_end();
+    set_params[0] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_CIPHER,
+        "AES-128-CTR", 0);
+    set_params[1] = OSSL_PARAM_construct_end();
+
+    if (!TEST_ptr(kctx = get_kdfbyname(OSSL_KDF_NAME_SRTPKDF))
+        || !TEST_size_t_eq(EVP_KDF_CTX_get_kdf_size(kctx), 0)
+        || !TEST_false(EVP_KDF_CTX_get_params(kctx, get_params))
+        || !TEST_true(EVP_KDF_CTX_set_params(kctx, set_params))
+        || !TEST_size_t_eq(EVP_KDF_CTX_get_kdf_size(kctx), 16))
+        goto err;
+
+    EVP_KDF_CTX_reset(kctx);
+    ret = TEST_size_t_eq(EVP_KDF_CTX_get_kdf_size(kctx), 0);
+err:
+    EVP_KDF_CTX_free(kctx);
+    return ret;
+}
+#endif /* OPENSSL_NO_SRTPKDF */
+
 #ifndef OPENSSL_NO_SSHKDF
 static int test_kdf_sshkdf(void)
 {
@@ -2477,6 +2506,9 @@ int setup_tests(void)
     ADD_TEST(test_kdf_ss_hmac);
     ADD_TEST(test_kdf_ss_kmac);
 #endif
+#ifndef OPENSSL_NO_SRTPKDF
+    ADD_TEST(test_kdf_srtpkdf_size);
+#endif
 #ifndef OPENSSL_NO_SSHKDF
     ADD_TEST(test_kdf_sshkdf);
 #endif