mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-03 03:31:41 +03:00
fix(protocomm): free response buffers on 2nd psa_cipher_update failure
In handle_session_command1(), if the second psa_cipher_update() call (encrypting the device verify data to send back to the client) fails, the error path only frees the outbuf ciphertext buffer. The out (Sec1Payload) and out_resp (SessionResp1) structures allocated just before it are never freed, and neither the cipher operation (cur_session->ctx_aes) nor the imported key (key_id) are released. The caller (sec1_req_handler(), via sec1_session_setup()) returns immediately on a non-ESP_OK result without doing any cleanup of its own here - sec1_session_setup_cleanup() only runs on the success path, once resp->sec1 has actually been assigned - so nothing else ever frees these on this path. Add psa_cipher_abort()/psa_destroy_key() and free() for out/out_resp, matching the cleanup already done for every other failure branch earlier in this same function. Fixes #18804 Signed-off-by: yi chen <94xhn1@gmail.com>
This commit is contained in:
@@ -196,7 +196,11 @@ static esp_err_t handle_session_command1(session_t *cur_session,
|
||||
status = psa_cipher_update(&cur_session->ctx_aes, cur_session->client_pubkey, sizeof(cur_session->client_pubkey), outbuf, PUBLIC_KEY_LEN, &outlen);
|
||||
if (status != PSA_SUCCESS) {
|
||||
ESP_LOGE(TAG, "Failed at psa_cipher_update with error code : %d", status);
|
||||
psa_cipher_abort(&cur_session->ctx_aes);
|
||||
psa_destroy_key(key_id);
|
||||
free(outbuf);
|
||||
free(out_resp);
|
||||
free(out);
|
||||
return ESP_FAIL;
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user