--- crypto/openssl/ssl/d1_lib.c.orig +++ crypto/openssl/ssl/d1_lib.c @@ -416,6 +416,23 @@ } dtls1_start_timer(s); + + /* + * If write_state is anything other than WRITE_STATE_TRANSITION, a write + * is still parked mid-flight (WANT_WRITE) from a previous call into the + * state machine - the current flight hasn't actually finished going out + * yet, so there's nothing valid to retransmit. Retransmitting anyway + * would reconstruct an already-sent message from the retransmit queue + * into s->init_buf/s->init_off/s->init_num/s->d1->w_msg - the same + * fields the parked write is still using - corrupting that write's + * state out from under it. Leave it alone and let the next + * SSL_read()/SSL_write()/SSL_accept()/SSL_connect() call resume the + * parked write normally instead. + */ + if (s->statem.state == MSG_FLOW_WRITING + && s->statem.write_state != WRITE_STATE_TRANSITION) + return 0; + /* Calls SSLfatal() if required */ return dtls1_retransmit_buffered_messages(s); } --- crypto/openssl/ssl/statem/statem_dtls.c.orig +++ crypto/openssl/ssl/statem/statem_dtls.c @@ -1196,6 +1196,8 @@ memcpy(s->init_buf->data, frag->fragment, frag->msg_header.msg_len + header_length); s->init_num = frag->msg_header.msg_len + header_length; + /* Always retransmit from the start, not wherever init_off was left */ + s->init_off = 0; dtls1_set_message_header_int(s, frag->msg_header.type, frag->msg_header.msg_len,