From 179c353f564ec7ada64b87730b25fb41107babd7 Mon Sep 17 00:00:00 2001 From: "djm@openbsd.org" Date: Tue, 13 Oct 2015 00:21:27 +0000 Subject: [PATCH] upstream commit free the correct IV length, don't assume it's always the cipher blocksize; ok dtucker@ Upstream-ID: c260d9e5ec73628d9ff4b067fbb060eff5a7d298 --- kex.c | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/kex.c b/kex.c index 5f72f2e9f..d8793b919 100644 --- a/kex.c +++ b/kex.c @@ -1,4 +1,4 @@ -/* $OpenBSD: kex.c,v 1.110 2015/08/21 23:57:48 djm Exp $ */ +/* $OpenBSD: kex.c,v 1.111 2015/10/13 00:21:27 djm Exp $ */ /* * Copyright (c) 2000, 2001 Markus Friedl. All rights reserved. * @@ -481,7 +481,7 @@ kex_free_newkeys(struct newkeys *newkeys) newkeys->enc.key = NULL; } if (newkeys->enc.iv) { - explicit_bzero(newkeys->enc.iv, newkeys->enc.block_size); + explicit_bzero(newkeys->enc.iv, newkeys->enc.iv_len); free(newkeys->enc.iv); newkeys->enc.iv = NULL; }