diff options
| author | Nathaniel J. Smith <njs@pobox.com> | 2017-06-08 04:14:44 -0700 |
|---|---|---|
| committer | Serhiy Storchaka <storchaka@gmail.com> | 2017-06-08 14:14:44 +0300 |
| commit | 54ba41ecc5711f89841342c5f9dd555ee13404b5 (patch) | |
| tree | cef59d99b7deacfcb9679201e35fcb731d436fb6 /Modules | |
| parent | e3a0ce2edea8082c8ae74ae03e04ce5dd1b52de4 (diff) | |
| download | cpython-git-54ba41ecc5711f89841342c5f9dd555ee13404b5.tar.gz | |
[3.5] bpo-30594: Fixed refcounting in newPySSLSocket (GH-1992) (#1993)
If pass a server_hostname= that fails IDNA decoding to SSLContext.wrap_socket or SSLContext.wrap_bio, then the SSLContext object had a spurious Py_DECREF called on it, eventually leading to segfaults.
(cherry picked from commit 65ece7ca2366308fa91a39a8dfa255e6bdce3cca)
Diffstat (limited to 'Modules')
| -rw-r--r-- | Modules/_ssl.c | 3 |
1 files changed, 1 insertions, 2 deletions
diff --git a/Modules/_ssl.c b/Modules/_ssl.c index 9f79d17f6d..3b2d3add28 100644 --- a/Modules/_ssl.c +++ b/Modules/_ssl.c @@ -570,6 +570,7 @@ newPySSLSocket(PySSLContext *sslctx, PySocketSockObject *sock, self->ssl = NULL; self->Socket = NULL; self->ctx = sslctx; + Py_INCREF(sslctx); self->shutdown_seen_zero = 0; self->handshake_done = 0; self->owner = NULL; @@ -584,8 +585,6 @@ newPySSLSocket(PySSLContext *sslctx, PySocketSockObject *sock, self->server_hostname = hostname; } - Py_INCREF(sslctx); - /* Make sure the SSL error state is initialized */ (void) ERR_get_state(); ERR_clear_error(); |
