Fix memory leak in mbedtls_mpi_sub_abs

Fix a memory leak in mbedtls_mpi_sub_abs when the output parameter is
aliased to the second operand (X = A - X) and the result is negative.

Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com>
This commit is contained in:
Gilles Peskine 2020-07-23 01:16:46 +02:00
parent e7876341af
commit 91070e43a6

View File

@ -1201,7 +1201,10 @@ int mbedtls_mpi_sub_abs( mbedtls_mpi *X, const mbedtls_mpi *A, const mbedtls_mpi
/* If we ran out of space for the carry, it means that the result /* If we ran out of space for the carry, it means that the result
* is negative. */ * is negative. */
if( n == X->n ) if( n == X->n )
return( MBEDTLS_ERR_MPI_NEGATIVE_VALUE ); {
ret = MBEDTLS_ERR_MPI_NEGATIVE_VALUE;
goto cleanup;
}
--X->p[n]; --X->p[n];
} }