From 65794347b7933b41026a13f6bb66592674804b8b Mon Sep 17 00:00:00 2001 From: David Benjamin Date: Fri, 25 Jan 2019 17:27:00 -0600 Subject: [PATCH] crypto: fix malloc mixing in X509ToObject EC_KEY_key2buf returns an OPENSSL_malloc'd pointer so it shouldn't be passed into Buffer::New, which expect a libc malloc'd pointer. Instead, factor out the ECDH::GetPublicKey code which uses EC_POINT_point2oct. This preserves the existing behavior where encoding failures are silently ignored, but it is probably safe to CHECK fail them instead. PR-URL: https://github.com/nodejs/node/pull/25717 Reviewed-By: James M Snell Reviewed-By: Anna Henningsen --- src/node_crypto.cc | 77 +++++++++++++++++++--------------------------- 1 file changed, 31 insertions(+), 46 deletions(-) diff --git a/src/node_crypto.cc b/src/node_crypto.cc index 3563eb141a..3a36a57d0b 100644 --- a/src/node_crypto.cc +++ b/src/node_crypto.cc @@ -1628,6 +1628,25 @@ static void AddFingerprintDigest(const unsigned char* md, } } +static MaybeLocal ECPointToBuffer(Environment* env, + const EC_GROUP* group, + const EC_POINT* point, + point_conversion_form_t form) { + size_t len = EC_POINT_point2oct(group, point, form, nullptr, 0, nullptr); + if (len == 0) { + env->ThrowError("Failed to get public key length"); + return MaybeLocal(); + } + MallocedBuffer buf( + len, env->isolate()->GetArrayBufferAllocator()); + len = EC_POINT_point2oct(group, point, form, buf.data, buf.size, nullptr); + if (len == 0) { + env->ThrowError("Failed to get public key"); + return MaybeLocal(); + } + return Buffer::New(env, buf.release(), len); +} + static Local X509ToObject(Environment* env, X509* cert) { EscapableHandleScope scope(env->isolate()); Local context = env->context(); @@ -1744,16 +1763,12 @@ static Local X509ToObject(Environment* env, X509* cert) { } } - unsigned char* pub = nullptr; - size_t publen = EC_KEY_key2buf(ec.get(), EC_KEY_get_conv_form(ec.get()), - &pub, nullptr); - if (publen > 0) { - Local buf = Buffer::New(env, pub, publen).ToLocalChecked(); - // Ownership of pub pointer accepted by Buffer. - pub = nullptr; + const EC_POINT* pubkey = EC_KEY_get0_public_key(ec.get()); + if (pubkey != nullptr) { + Local buf = + ECPointToBuffer(env, group, pubkey, EC_KEY_get_conv_form(ec.get())) + .ToLocalChecked(); info->Set(context, env->pubkey_string(), buf).FromJust(); - } else { - CHECK_NULL(pub); } const int nid = EC_GROUP_get_curve_name(group); @@ -4548,28 +4563,14 @@ void ECDH::GetPublicKey(const FunctionCallbackInfo& args) { if (pub == nullptr) return env->ThrowError("Failed to get ECDH public key"); - int size; CHECK(args[0]->IsUint32()); uint32_t val = args[0].As()->Value(); point_conversion_form_t form = static_cast(val); - size = EC_POINT_point2oct(ecdh->group_, pub, form, nullptr, 0, nullptr); - if (size == 0) - return env->ThrowError("Failed to get public key length"); - - auto* allocator = env->isolate()->GetArrayBufferAllocator(); - unsigned char* out = - static_cast(allocator->AllocateUninitialized(size)); - - int r = EC_POINT_point2oct(ecdh->group_, pub, form, out, size, nullptr); - if (r != size) { - allocator->Free(out, size); - return env->ThrowError("Failed to get public key"); - } - - Local buf = - Buffer::New(env, reinterpret_cast(out), size).ToLocalChecked(); - args.GetReturnValue().Set(buf); + MaybeLocal buf = + ECPointToBuffer(env, EC_KEY_get0_group(ecdh->key_.get()), pub, form); + if (buf.IsEmpty()) return; + args.GetReturnValue().Set(buf.ToLocalChecked()); } @@ -5177,25 +5178,9 @@ void ConvertKey(const FunctionCallbackInfo& args) { uint32_t val = args[2].As()->Value(); point_conversion_form_t form = static_cast(val); - int size = EC_POINT_point2oct( - group.get(), pub.get(), form, nullptr, 0, nullptr); - - if (size == 0) - return env->ThrowError("Failed to get public key length"); - - auto* allocator = env->isolate()->GetArrayBufferAllocator(); - unsigned char* out = - static_cast(allocator->AllocateUninitialized(size)); - - int r = EC_POINT_point2oct(group.get(), pub.get(), form, out, size, nullptr); - if (r != size) { - allocator->Free(out, size); - return env->ThrowError("Failed to get public key"); - } - - Local buf = - Buffer::New(env, reinterpret_cast(out), size).ToLocalChecked(); - args.GetReturnValue().Set(buf); + MaybeLocal buf = ECPointToBuffer(env, group.get(), pub.get(), form); + if (buf.IsEmpty()) return; + args.GetReturnValue().Set(buf.ToLocalChecked()); }