Commit 680cc06066 for openssl.org
commit 680cc06066601d541e99604718806eb6cb601c0d
Author: mzfr <github@mzfr.in>
Date: Wed Sep 23 19:26:17 2026 +0800
srtpkdf: avoid NULL dereference in size queries
Return an error when the cipher has not been configured instead of
passing NULL to EVP_CIPHER_get_key_length(). Add regression coverage
for fresh, configured, and reset contexts.
Fixes #32945
Reviewed-by: Paul Dale <paul.dale@oracle.com>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Merge-date: Fri Oct 2 08:12:15 2026
Merged-from: https://github.com/openssl/openssl/pull/32959
diff --git a/providers/implementations/kdfs/srtpkdf.c b/providers/implementations/kdfs/srtpkdf.c
index 4ae77aedee..e55a404257 100644
--- a/providers/implementations/kdfs/srtpkdf.c
+++ b/providers/implementations/kdfs/srtpkdf.c
@@ -303,7 +303,12 @@ static int kdf_srtpkdf_get_ctx_params(void *vctx, OSSL_PARAM params[])
return 0;
if (p.size != NULL) {
- size_t sz = EVP_CIPHER_key_length(ossl_prov_cipher_cipher(&ctx->cipher));
+ const EVP_CIPHER *cipher = ossl_prov_cipher_cipher(&ctx->cipher);
+ size_t sz;
+
+ if (cipher == NULL)
+ return 0;
+ sz = EVP_CIPHER_key_length(cipher);
if (!OSSL_PARAM_set_size_t(p.size, sz))
return 0;
diff --git a/test/evp_kdf_test.c b/test/evp_kdf_test.c
index 6d4a55d11e..01e2726b71 100644
--- a/test/evp_kdf_test.c
+++ b/test/evp_kdf_test.c
@@ -1988,6 +1988,35 @@ static int test_kdf_ss_kmac(void)
}
#endif /* OPENSSL_NO_SSKDF */
+#ifndef OPENSSL_NO_SRTPKDF
+static int test_kdf_srtpkdf_size(void)
+{
+ int ret = 0;
+ size_t size = 0;
+ EVP_KDF_CTX *kctx = NULL;
+ OSSL_PARAM get_params[2], set_params[2];
+
+ get_params[0] = OSSL_PARAM_construct_size_t(OSSL_KDF_PARAM_SIZE, &size);
+ get_params[1] = OSSL_PARAM_construct_end();
+ set_params[0] = OSSL_PARAM_construct_utf8_string(OSSL_KDF_PARAM_CIPHER,
+ "AES-128-CTR", 0);
+ set_params[1] = OSSL_PARAM_construct_end();
+
+ if (!TEST_ptr(kctx = get_kdfbyname(OSSL_KDF_NAME_SRTPKDF))
+ || !TEST_size_t_eq(EVP_KDF_CTX_get_kdf_size(kctx), 0)
+ || !TEST_false(EVP_KDF_CTX_get_params(kctx, get_params))
+ || !TEST_true(EVP_KDF_CTX_set_params(kctx, set_params))
+ || !TEST_size_t_eq(EVP_KDF_CTX_get_kdf_size(kctx), 16))
+ goto err;
+
+ EVP_KDF_CTX_reset(kctx);
+ ret = TEST_size_t_eq(EVP_KDF_CTX_get_kdf_size(kctx), 0);
+err:
+ EVP_KDF_CTX_free(kctx);
+ return ret;
+}
+#endif /* OPENSSL_NO_SRTPKDF */
+
#ifndef OPENSSL_NO_SSHKDF
static int test_kdf_sshkdf(void)
{
@@ -2477,6 +2506,9 @@ int setup_tests(void)
ADD_TEST(test_kdf_ss_hmac);
ADD_TEST(test_kdf_ss_kmac);
#endif
+#ifndef OPENSSL_NO_SRTPKDF
+ ADD_TEST(test_kdf_srtpkdf_size);
+#endif
#ifndef OPENSSL_NO_SSHKDF
ADD_TEST(test_kdf_sshkdf);
#endif