gh-156293: Use-after-free for server-side SSLContext with sni_callback - #158504
Conversation
Documentation build overview
|
|
We should probably still set the backport tags to make it clear it should get backported that far, even if the automatic one is likely to fail. |
…allback Co-authored-by: Gregory P. Smith <68491+gpshead@users.noreply.github.com>
402015d to
0f63c2a
Compare
|
I set the wrong GitHub issue, so I've had to force-push to fix that on the commit and in the GH PR (too many reserved, will have to be more careful about that in the future). |
|
Thanks @sethmlarson for the PR, and @hugovk for merging it 🌮🎉.. I'm working now to backport this PR to: 3.11, 3.12, 3.13, 3.14, 3.15. |
|
Sorry, @sethmlarson and @hugovk, I could not cleanly backport this to |
|
GH-158514 is a backport of this pull request to the 3.15 branch. |
|
Sorry, @sethmlarson and @hugovk, I could not cleanly backport this to |
|
GH-158515 is a backport of this pull request to the 3.14 branch. |
|
Sorry, @sethmlarson and @hugovk, I could not cleanly backport this to |
|
I have a stack of backport PR branches ready for this, they were pushed to the GHSA private fork IIRC, see the GHSA |
|
See my gpshead fork's |
|
We already have 3.12-3.15 backports merged. I'll open 3.10-3.11 backports from the ready forks at Edit: I don't need to, Greg did it :) |
|
GH-158523 is a backport of this pull request to the 3.11 branch. |
|
GH-158524 is a backport of this pull request to the 3.10 branch. |
…callback (GH-158504) (#158524) * [3.10] gh-156293: ssl: do not call the servername callback through a released SSLContext The servername (SNI) callback located its SSLContext through a borrowed pointer registered with OpenSSL, which can outlive the SSLContext object. Look the context up from the SSL object instead, and unregister the callback when the context is deallocated. Backport of 87665c9, adapted to this branch's servername callback code. * [3.10] gh-156293: Document sni_callback dispatch after a context switch
…callback (GH-158504) (#158523) * [3.11] gh-156293: ssl: do not call the servername callback through a released SSLContext The servername (SNI) callback located its SSLContext through a borrowed pointer registered with OpenSSL, which can outlive the SSLContext object. Look the context up from the SSL object instead, and unregister the callback when the context is deallocated. Backport of 87665c9, adapted to this branch's servername callback code. * [3.11] gh-156293: Document sni_callback dispatch after a context switch
I believe this needs to be backported manually beyond 3.13? (cc @gpshead) I can create those PRs.