Backport 2.1:Fix crash when calling `mbedtls_ssl_cache_free` twice
Set `cache` to zero at the end of `mbedtls_ssl_cache_free` #1104
diff --git a/library/ssl_cache.c b/library/ssl_cache.c
index 711bc53..47107b6 100644
--- a/library/ssl_cache.c
+++ b/library/ssl_cache.c
@@ -43,6 +43,15 @@
#define mbedtls_free free
#endif
+#include "mbedtls/ssl_cache.h"
+
+#include <string.h>
+
+/* Implementation that should never be optimized out by the compiler */
+static void mbedtls_zeroize( void *v, size_t n ) {
+ volatile unsigned char *p = v; while( n-- ) *p++ = 0;
+}
+
void mbedtls_ssl_cache_init( mbedtls_ssl_cache_context *cache )
{
memset( cache, 0, sizeof( mbedtls_ssl_cache_context ) );
@@ -321,6 +330,8 @@
#if defined(MBEDTLS_THREADING_C)
mbedtls_mutex_free( &cache->mutex );
#endif
+
+ mbedtls_zeroize( cache, sizeof(mbedtls_ssl_cache_context) );
}
#endif /* MBEDTLS_SSL_CACHE_C */