Skip to content

Fix memory leaks in wolfSSL_d2i_OCSP_RESPONSE reuse branch. Avoid using stale nonces when OCSP stapling is enabled at the context level. - #11628

Open
kareem-wolfssl wants to merge 3 commits into
wolfSSL:masterfrom
kareem-wolfssl:zd22448_ocsp
Open

kareem-wolfssl wants to merge 3 commits into
wolfSSL:masterfrom
kareem-wolfssl:zd22448_ocsp

Conversation

@kareem-wolfssl

Copy link
Copy Markdown
Contributor

Description

Partially fixes zd#22448

Testing

Built in + added tests, reproducers

Checklist

  • added tests
  • updated/added doxygen
  • updated appropriate READMEs
  • Updated manual and documentation

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The new test breaks TLS-1.3-only builds, and the V2 nonce path lacks targeted coverage.

Review effort: Balanced
Findings: 1 High severity · 1 Low severity

Open (2)
What changed in this PR

Fixes OCSP response reuse leaks and stale context-level stapling nonces.

Changes:

  • Frees complete reused OCSP response chains and resets stale references.
  • Generates per-connection OCSP nonces.
  • Adds regression tests for response reuse and nonce freshness.
File Description
src/​ocsp.c Corrects OCSP response reuse cleanup.
src/​tls.c Refreshes context-configured stapling nonces.
tests/​api/​test_ocsp.c Adds OCSP regression tests.
tests/​api/​test_ocsp.h Declares new tests.
tests/​api.c Registers new tests.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread tests/api/test_ocsp.c
Comment thread src/tls.c
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants