Skip to content

fix: free RNG on encrypt error paths - #271

Merged
aidankeefe2022 merged 1 commit into
wolfSSL:mainfrom
MarkAtwood:fix/encrypt-rng-leak
Oct 1, 2026
Merged

aidankeefe2022 merged 1 commit into
wolfSSL:mainfrom
MarkAtwood:fix/encrypt-rng-leak

Conversation

@MarkAtwood

@MarkAtwood MarkAtwood commented Jul 9, 2026 •

Copy link
Copy Markdown
Contributor

Bug

wolfCLU_encrypt() in src/crypto/clu_encrypt.c calls wc_InitRng(&rng), which heap-allocates DRBG state when wolfSSL is built with HAVE_HASHDRBG (the default) and without WOLFSSL_NO_MALLOC/STATIC_MEMORY. The only wc_FreeRng(&rng) was on the success path. All 12 error-return paths after wc_InitRng returned without freeing the RNG, leaking the DRBG allocation on every early exit (RNG generate/genKey failure, output-file open failure, input/output alloc failure, hex conversion failure, file read/write errors, Camellia key/mode failures).

Fix

Insert wc_FreeRng(&rng); immediately before each early return that occurs after wc_InitRng succeeds. The InitRng-failure path is left untouched (no allocation to free on failure). No control-flow restructuring, so no risk of double-close/double-free.

Verification

Compiled the patched translation unit against a wolfSSL install (--enable-all, HAVE_HASHDRBG confirmed in options.h): gcc -c -I. -I<wolfssl>/include src/crypto/clu_encrypt.c exits 0; nm confirms wc_InitRng/wc_FreeRng are referenced (RNG code compiled and linked, not dead).

Reported by static analysis (Fenrir finding 579).

[fenrir-sweep:held]

Copilot AI review requested due to automatic review settings July 9, 2026 23:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot couldn't run its full agentic review because no GitHub Actions runner was available. Make sure your repository has a runner available to run Copilot's review, or add a copilot-setup-steps.yml file specifying one with the runs-on attribute. See the docs for more details.

Fixes a memory leak in wolfCLU_encrypt() by ensuring the wolfSSL RNG/DRBG state is freed on all early-return error paths occurring after successful RNG initialization.

Changes:

  • Added wc_FreeRng(&rng); before each post-wc_InitRng() early return to prevent DRBG heap leaks.
  • Kept the wc_InitRng() failure path unchanged to avoid freeing an uninitialized RNG.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread src/crypto/clu_encrypt.c
Comment thread src/crypto/clu_encrypt.c
@MarkAtwood
MarkAtwood marked this pull request as ready for review September 24, 2026 23:52

@aidankeefe2022 aidankeefe2022 left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Going to make a follow up PR with more fixes for this file it is a mess

@aidankeefe2022
aidankeefe2022 merged commit 2b3b8ce into wolfSSL:main Oct 1, 2026
17 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants