From a9de0c44fad13fe3046a2173cc760332aa44810e Mon Sep 17 00:00:00 2001 From: Juliusz Sosinowicz Date: Mon, 5 Oct 2026 10:40:08 +0000 Subject: [PATCH] x509: use an owned public key for -modulus wolfSSL is moving X509_get0_pubkey() to OpenSSL's borrowed semantics (wolfSSL PR #11428). The -modulus code freed that key, which with the new semantics is the certificate's own key, so X509_free() then hit a use after free. wolfSSL_X509_get_pubkey() returns a reference the caller owns with both old and new wolfSSL, so freeing it stays correct. --- src/x509/clu_cert_setup.c | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/src/x509/clu_cert_setup.c b/src/x509/clu_cert_setup.c index 1f05998b..7f669199 100644 --- a/src/x509/clu_cert_setup.c +++ b/src/x509/clu_cert_setup.c @@ -715,7 +715,7 @@ int wolfCLU_certSetup(int argc, char **argv) /* print modulus */ if (ret == WOLFCLU_SUCCESS && modulus) { EVP_PKEY *pkey; - pkey = X509_get0_pubkey(x509); + pkey = wolfSSL_X509_get_pubkey(x509); if (pkey == NULL) { wolfCLU_LogError("Modulus=unavailable"); @@ -756,8 +756,6 @@ int wolfCLU_certSetup(int argc, char **argv) char info[] = "Wrong Algorithm type"; wolfSSL_BIO_write(out, info, (int)XSTRLEN(info)); } - /* wolfSSL's X509_get0_pubkey maps to wolfSSL_X509_get_pubkey - * which allocates, unlike OpenSSL's borrowed-ref convention */ wolfSSL_EVP_PKEY_free(pkey); } }