From d9c66c0509953d702f6fb48479d5986cf0183541 Mon Sep 17 00:00:00 2001 From: Hanno Becker Date: Mon, 6 Aug 2018 11:35:16 +0100 Subject: [PATCH 1/3] Make alert sending function re-entrant Fixes #1916 Signed-off-by: Dave Rodgman --- library/ssl_msg.c | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/library/ssl_msg.c b/library/ssl_msg.c index 0b696dd56..0b1322d93 100644 --- a/library/ssl_msg.c +++ b/library/ssl_msg.c @@ -4918,6 +4918,9 @@ int mbedtls_ssl_send_alert_message( mbedtls_ssl_context *ssl, if( ssl == NULL || ssl->conf == NULL ) return( MBEDTLS_ERR_SSL_BAD_INPUT_DATA ); + if( ssl->out_left != 0 ) + return( mbedtls_ssl_flush_output( ssl ) ); + MBEDTLS_SSL_DEBUG_MSG( 2, ( "=> send alert message" ) ); MBEDTLS_SSL_DEBUG_MSG( 3, ( "send alert level=%u message=%u", level, message )); @@ -5790,9 +5793,6 @@ int mbedtls_ssl_close_notify( mbedtls_ssl_context *ssl ) MBEDTLS_SSL_DEBUG_MSG( 2, ( "=> write close notify" ) ); - if( ssl->out_left != 0 ) - return( mbedtls_ssl_flush_output( ssl ) ); - if( ssl->state == MBEDTLS_SSL_HANDSHAKE_OVER ) { if( ( ret = mbedtls_ssl_send_alert_message( ssl, From a349cfd585c855cb45639cd22669dbe772479439 Mon Sep 17 00:00:00 2001 From: Hanno Becker Date: Tue, 14 Aug 2018 16:38:12 +0100 Subject: [PATCH 2/3] Add ChangeLog entry Signed-off-by: Dave Rodgman --- ChangeLog.d/alert_reentrant.txt | 5 +++++ 1 file changed, 5 insertions(+) create mode 100644 ChangeLog.d/alert_reentrant.txt diff --git a/ChangeLog.d/alert_reentrant.txt b/ChangeLog.d/alert_reentrant.txt new file mode 100644 index 000000000..2d1dc602e --- /dev/null +++ b/ChangeLog.d/alert_reentrant.txt @@ -0,0 +1,5 @@ +Bugfix + * Fix bug in the alert sending function mbedtls_ssl_send_alert_message() + potentially leading to corrupted alert messages being sent in case + the function needs to be re-called after initially returning + MBEDTLS_SSL_WANT_WRITE. From 28fd4cd8e91897c18346a41a5f07019fb0902fbe Mon Sep 17 00:00:00 2001 From: Dave Rodgman Date: Fri, 8 Apr 2022 12:53:00 +0100 Subject: [PATCH 3/3] Update ChangeLog.d/alert_reentrant.txt Co-authored-by: Gilles Peskine Signed-off-by: Dave Rodgman --- ChangeLog.d/alert_reentrant.txt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/ChangeLog.d/alert_reentrant.txt b/ChangeLog.d/alert_reentrant.txt index 2d1dc602e..691d64c0d 100644 --- a/ChangeLog.d/alert_reentrant.txt +++ b/ChangeLog.d/alert_reentrant.txt @@ -2,4 +2,4 @@ Bugfix * Fix bug in the alert sending function mbedtls_ssl_send_alert_message() potentially leading to corrupted alert messages being sent in case the function needs to be re-called after initially returning - MBEDTLS_SSL_WANT_WRITE. + MBEDTLS_SSL_WANT_WRITE. Fixes #1916.