Commit 8de91c5254 for openssl.org
commit 8de91c52544d8685bde740c0a959f2c00adbbd87
Author: Neil Horman <nhorman@openssl.org>
Date: Tue Oct 6 08:58:53 2026 -0400
Fix deref before NULL check in ossl_method_store_fetch()
Coverity caught a deref before a NULL check error
in ossl_method_store_fetch(). Specifically, we check impl->archived == 1
prior to checking impl != NULL. An implementation in the stack should
never be NULL here, but if we are going to check for NULL, we should
do it prior to using the value we fetched.
Resolves: https://scan5.scan.coverity.com/#/project-view/60762/10222?selectedIssue=1702515
Fixes: 3233fe19a19a "Defer implementation freeing in method store until the libctx is freed"
Reviewed-by: Bob Beck <beck@openssl.org>
Reviewed-by: Andrew Dinh <andrewd@openssl.org>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Merge-date: Fri Oct 9 23:39:07 2026
Merged-from: https://github.com/openssl/openssl/pull/33120
diff --git a/crypto/property/property.c b/crypto/property/property.c
index 66c2023f29..673a690d47 100644
--- a/crypto/property/property.c
+++ b/crypto/property/property.c
@@ -815,10 +815,10 @@ int ossl_method_store_fetch(OSSL_METHOD_STORE *store,
if (pq == NULL) {
for (j = 0; j < sk_IMPLEMENTATION_num(alg->impls); j++) {
impl = sk_IMPLEMENTATION_value(alg->impls, j);
- if (impl->archived == 1)
+ if (impl == NULL || impl->archived == 1)
continue;
- if (impl != NULL
- && (prov == NULL || impl->provider == prov)) {
+
+ if (prov == NULL || impl->provider == prov) {
best_impl = impl;
ret = 1;
break;