mirror of
https://github.com/Mbed-TLS/mbedtls.git
synced 2026-07-30 16:26:33 +08:00
Merge pull request #1603 from bjwtaylor/oob-key-exchange-restricted
Add fix for OOB key exchange error
This commit is contained in:
commit
8efcd8d700
4
ChangeLog.d/oob-key-exchange-restricted.txt
Normal file
4
ChangeLog.d/oob-key-exchange-restricted.txt
Normal file
@ -0,0 +1,4 @@
|
||||
Security
|
||||
* Fix an out-of-bounds read when parsing TLS 1.2 ECJPAKE ServerKeyExchange
|
||||
messages. Reported-by Biniam Demissie.
|
||||
CVE-2026-50588
|
||||
@ -1931,6 +1931,8 @@ start_processing:
|
||||
* However since we only support secp256r1 for now, we check only
|
||||
* that TLS ID here
|
||||
*/
|
||||
MBEDTLS_SSL_CHK_BUF_READ_PTR(p, end, 3);
|
||||
|
||||
uint16_t read_tls_id = MBEDTLS_GET_UINT16_BE(p, 1);
|
||||
uint16_t exp_tls_id = mbedtls_ssl_get_tls_id_from_ecp_group_id(
|
||||
MBEDTLS_ECP_DP_SECP256R1);
|
||||
|
||||
Loading…
x
Reference in New Issue
Block a user