Commit 77bdd80927d for php

commit 77bdd80927d9440d17be7dce7c06a2cc2292b40a
Author: Alexander Danilov <adapik@yandex.ru>
Date:   Tue Sep 29 20:54:39 2026 +0300

    openssl: Fix memory leak by doing early salt validation

    Closes GH-23999.

diff --git a/NEWS b/NEWS
index 18d07cc32ff..478e2291210 100644
--- a/NEWS
+++ b/NEWS
@@ -37,6 +37,7 @@ PHP                                                                        NEWS
 - OpenSSL:
   . Fixed stream_socket_enable_crypto() leaving the socket non-blocking
     after a handshake timeout. (Ilia Alshanetsky)
+  . Fix memory leak by doing early salt validation. (adapik)

 - PCNTL:
   . Fixed pcntl_signal_dispatch() dropping the queued signals when it runs while
diff --git a/ext/openssl/openssl.c b/ext/openssl/openssl.c
index 5ea2a773743..6ec8a11734a 100644
--- a/ext/openssl/openssl.c
+++ b/ext/openssl/openssl.c
@@ -4556,6 +4556,8 @@ PHP_FUNCTION(openssl_sign)
 		Z_PARAM_LONG(salt_length)
 	ZEND_PARSE_PARAMETERS_END();

+	PHP_OPENSSL_CHECK_LONG_TO_INT(salt_length, salt_length, 6);
+
 	pkey = php_openssl_pkey_from_zval(key, 0, "", 0, 3);
 	if (pkey == NULL) {
 		if (!EG(exception)) {
@@ -4574,7 +4576,6 @@ PHP_FUNCTION(openssl_sign)
 		php_error_docref(NULL, E_WARNING, "Unknown digest algorithm");
 		RETURN_FALSE;
 	}
-	PHP_OPENSSL_CHECK_LONG_TO_INT(salt_length, salt_length, 6);

 	md_ctx = EVP_MD_CTX_create();
 	size_t siglen;