mirror of
https://github.com/yuzu-emu/mbedtls.git
synced 2025-01-26 21:11:06 +00:00
Backport 1.3:Set PEM buffer to zero before freeing it
Set PEM buffer to zero before freeing it, to avoid private keys being leaked to memory after releasing it.
This commit is contained in:
parent
a75a459143
commit
27ce0b5ff1
|
@ -1,5 +1,11 @@
|
|||
mbed TLS ChangeLog (Sorted per branch, date)
|
||||
|
||||
= mbed TLS x.x.x branch released xxxx-xx-xx
|
||||
|
||||
Security
|
||||
* Set PEM buffer to zero before freeing it, to avoid decoded private keys
|
||||
being leaked to memory after release.
|
||||
|
||||
= mbed TLS 1.3.21 branch released 2017-08-10
|
||||
|
||||
Security
|
||||
|
|
|
@ -389,6 +389,8 @@ int pem_read_buffer( pem_context *ctx, const char *header, const char *footer,
|
|||
|
||||
void pem_free( pem_context *ctx )
|
||||
{
|
||||
if ( ctx->buf != NULL )
|
||||
polarssl_zeroize( ctx->buf, ctx->buflen );
|
||||
polarssl_free( ctx->buf );
|
||||
polarssl_free( ctx->info );
|
||||
|
||||
|
|
Loading…
Reference in a new issue