From: djm Date: Tue, 13 Oct 2015 00:21:27 +0000 (+0000) Subject: free the correct IV length, don't assume it's always the cipher X-Git-Url: http://artulab.com/gitweb/?a=commitdiff_plain;h=28190e8af9439e673bdde68df942891737c849be;p=openbsd free the correct IV length, don't assume it's always the cipher blocksize; ok dtucker@ --- diff --git a/usr.bin/ssh/kex.c b/usr.bin/ssh/kex.c index 05628732f96..111a3e52f48 100644 --- a/usr.bin/ssh/kex.c +++ b/usr.bin/ssh/kex.c @@ -1,4 +1,4 @@ -/* $OpenBSD: kex.c,v 1.110 2015/08/21 23:57:48 djm Exp $ */ +/* $OpenBSD: kex.c,v 1.111 2015/10/13 00:21:27 djm Exp $ */ /* * Copyright (c) 2000, 2001 Markus Friedl. All rights reserved. * @@ -462,7 +462,7 @@ kex_free_newkeys(struct newkeys *newkeys) newkeys->enc.key = NULL; } if (newkeys->enc.iv) { - explicit_bzero(newkeys->enc.iv, newkeys->enc.block_size); + explicit_bzero(newkeys->enc.iv, newkeys->enc.iv_len); free(newkeys->enc.iv); newkeys->enc.iv = NULL; }