summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorcypherbridge <[email protected]>2025-05-27 19:01:20 -0700
committerGitHub <[email protected]>2025-05-27 19:01:20 -0700
commitef78bf896fd4deb46d1f4e63ffe9a2a6ecab2887 (patch)
treece97cb5b23d0161b07fcd8051491519e109b437c
parent5af33d7d55e67dc93ddff52ec6eb74674c69cbb7 (diff)
patch for GHSA-5vrv-8j5h-h6h6
edited by inspection not compiled or run-time tested
-rw-r--r--nx_secure/src/nx_secure_tls_process_clienthello.c12
1 files changed, 12 insertions, 0 deletions
diff --git a/nx_secure/src/nx_secure_tls_process_clienthello.c b/nx_secure/src/nx_secure_tls_process_clienthello.c
index 8878d81e..0e831a16 100644
--- a/nx_secure/src/nx_secure_tls_process_clienthello.c
+++ b/nx_secure/src/nx_secure_tls_process_clienthello.c
@@ -280,6 +280,12 @@ USHORT no_extension = NX_FALSE;
length += session_id_length;
}
+ /* GHSA-5vrv-8j5h-h6h6 2504xx */
+ if ((length + 1) >= message_length)
+ {
+ return(NX_SECURE_TLS_INCORRECT_MESSAGE_LENGTH);
+ }
+
/* Negotiate the ciphersuite we want to use. */
ciphersuite_list_length = (USHORT)((packet_buffer[length] << 8) + packet_buffer[length + 1]);
length += 2;
@@ -294,6 +300,12 @@ USHORT no_extension = NX_FALSE;
length += ciphersuite_list_length;
+ /* GHSA-5vrv-8j5h-h6h6 2504xx */
+ if (length >= message_length)
+ {
+ return(NX_SECURE_TLS_INCORRECT_MESSAGE_LENGTH);
+ }
+
/* Compression methods length - one byte. For now we only support the NULL method. */
compression_methods_length = packet_buffer[length];
length++;