Page MenuHomeFreeBSD

ktls: Fix an off-by-one bug in tls13_find_record_type()
AcceptedPublic

Authored by markj on Thu, Sep 17, 4:54 PM.
Tags
None
Referenced Files
F172389396: D59767.diff
Fri, Sep 18, 3:50 AM
F172389304: D59767.id186976.diff
Fri, Sep 18, 3:50 AM
F172356998: D59767.id186976.diff
Thu, Sep 17, 10:35 PM
F172356670: D59767.diff
Thu, Sep 17, 10:32 PM
Subscribers

Details

Reviewers
jhb
gallatin
Summary

If the entire plaintext is zero-filled, the backwards walk in
tls13_find_record_type() would return the offset of the last byte of the
TLS header. This causes an underflow when decrypting, resulting in a
null pointer dereference.

Fix the condition and add a regression test.

Diff Detail

Repository
rG FreeBSD src repository
Lint
Lint Skipped
Unit
Tests Skipped
Build Status
Buildable 77027
Build 73910: arc lint + arc unit