diff options
| author | cypherbridge <[email protected]> | 2025-05-27 19:01:20 -0700 |
|---|---|---|
| committer | GitHub <[email protected]> | 2025-05-27 19:01:20 -0700 |
| commit | ef78bf896fd4deb46d1f4e63ffe9a2a6ecab2887 (patch) | |
| tree | ce97cb5b23d0161b07fcd8051491519e109b437c | |
| parent | 5af33d7d55e67dc93ddff52ec6eb74674c69cbb7 (diff) | |
patch for GHSA-5vrv-8j5h-h6h6
edited by inspection not compiled or run-time tested
| -rw-r--r-- | nx_secure/src/nx_secure_tls_process_clienthello.c | 12 |
1 files changed, 12 insertions, 0 deletions
diff --git a/nx_secure/src/nx_secure_tls_process_clienthello.c b/nx_secure/src/nx_secure_tls_process_clienthello.c index 8878d81e..0e831a16 100644 --- a/nx_secure/src/nx_secure_tls_process_clienthello.c +++ b/nx_secure/src/nx_secure_tls_process_clienthello.c @@ -280,6 +280,12 @@ USHORT no_extension = NX_FALSE; length += session_id_length; } + /* GHSA-5vrv-8j5h-h6h6 2504xx */ + if ((length + 1) >= message_length) + { + return(NX_SECURE_TLS_INCORRECT_MESSAGE_LENGTH); + } + /* Negotiate the ciphersuite we want to use. */ ciphersuite_list_length = (USHORT)((packet_buffer[length] << 8) + packet_buffer[length + 1]); length += 2; @@ -294,6 +300,12 @@ USHORT no_extension = NX_FALSE; length += ciphersuite_list_length; + /* GHSA-5vrv-8j5h-h6h6 2504xx */ + if (length >= message_length) + { + return(NX_SECURE_TLS_INCORRECT_MESSAGE_LENGTH); + } + /* Compression methods length - one byte. For now we only support the NULL method. */ compression_methods_length = packet_buffer[length]; length++; |
