Skip to content

Fix a probable a null pointer exception - #1907

Closed
openrefactorymunawar wants to merge 1 commit into
bcgit:1.78.1from
openrefactorymunawar:patch-1
Closed

Fix a probable a null pointer exception#1907
openrefactorymunawar wants to merge 1 commit into
bcgit:1.78.1from
openrefactorymunawar:patch-1

Conversation

@openrefactorymunawar

Copy link
Copy Markdown

In file ExtendedPKIXParameters.java, inside method setTrustedACIssuers, there is a potential null pointer dereference. This is because a method is called on an object just after checking that the object is null.

This is perhaps done by mistake. The bug was not triggered before, because the setTrustedACIssuers method was never called with a null Set in the code or in the test cases. It also appears as not intended to throw a null pointer exception deliberately. This is because JavaDoc comments note that the method may throw a ClassCastException, but the comments do not mention any null pointer exception. The JavaDoc says that the formal parameter should not be null, but there are no enforcement of that, and if someone wants to send a null, there is a null pointer exception.

This awkward code should be removed. The pull request suggests that removal.

Sponsorship and Support:

This work is done by the security researchers from OpenRefactory and is supported by the Open Source Security Foundation (OpenSSF): Project Alpha-Omega. Alpha-Omega is a project partnering with open source software project maintainers to systematically find new, as-yet-undiscovered vulnerabilities in open source code - and get them fixed – to improve global software supply chain security.

The bug is found by running the Intelligent Code Repair (iCR) tool by OpenRefactory and then manually triaging the results.

@hubot
hubot deleted the branch bcgit:1.78.1 February 10, 2025 04:56
@dghgit

dghgit commented Sep 14, 2025

Copy link
Copy Markdown
Contributor

Thanks for the patch. Merged!

@dghgit dghgit closed this Sep 14, 2025
markus-jung-vivavis added a commit to markus-jung-vivavis/bc-java that referenced this pull request Nov 10, 2025
* 1.82: (1360 commits)
  partial addition of Java25 support
  removed overlap check (unsafe)
  minor compatibility fixes.
  minor compatibility fixes. updated to 1.82.
  Pqc hqc update v5
  removed unnecessary public "internal" method.
  updated from PR list
  updated with current 1.82 PRs and bug fixes
  added PQC sigs
  further clean up of old algorithm names
  added named PREHASH algorithms - relates to github bcgit#2162 cleaned up algorithm list for composites.
  Added publish.gradle stub
  added purpose check, marked deprecated method
  corrected CertPath issue - relates to github bcgit#2152
  set name of artifact to bc-<version>-bom
  fixed probable null pointer issue - relates to github bcgit#1907
  merge of github bcgit#2123 with minor corrections
  error prone fix.
  added parameter setting to allow for pre-hash calculation - relates to github bcgit#2162
  removed use of deprecated class
  ...
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants