Re: [Openvpn-devel] [PATCH] Fix memory leak in x509_verify_cert_ku()

2017-05-08 Thread Steffan Karger
Hi, On 08-05-17 16:54, David Sommerseth wrote: > On 07/05/17 13:01, Steffan Karger wrote: > > result_t > x509_verify_cert_ku(X509 *x509, const unsigned *const expected_ku, > int expected_len) > { > ASN1_BI

Re: [Openvpn-devel] [PATCH] Fix memory leak in x509_verify_cert_ku()

2017-05-08 Thread David Sommerseth
On 07/05/17 13:01, Steffan Karger wrote: > If keyUsage was only required to be present, but no specific value was > required, we would omit to free the extracted string. This happens as of > 2.4.1, if --remote-cert-tls is used. In that case we leak a bit of > memory on each TLS (re)negotiation. >

[Openvpn-devel] [PATCH] Fix memory leak in x509_verify_cert_ku()

2017-05-07 Thread Steffan Karger
If keyUsage was only required to be present, but no specific value was required, we would omit to free the extracted string. This happens as of 2.4.1, if --remote-cert-tls is used. In that case we leak a bit of memory on each TLS (re)negotiation. Signed-off-by: Steffan Karger --- Changes.rst