From ef78bf896fd4deb46d1f4e63ffe9a2a6ecab2887 Mon Sep 17 00:00:00 2001 From: cypherbridge Date: Tue, 27 May 2025 19:01:20 -0700 Subject: patch for GHSA-5vrv-8j5h-h6h6 edited by inspection not compiled or run-time tested --- nx_secure/src/nx_secure_tls_process_clienthello.c | 12 ++++++++++++ 1 file changed, 12 insertions(+) diff --git a/nx_secure/src/nx_secure_tls_process_clienthello.c b/nx_secure/src/nx_secure_tls_process_clienthello.c index 8878d81e..0e831a16 100644 --- a/nx_secure/src/nx_secure_tls_process_clienthello.c +++ b/nx_secure/src/nx_secure_tls_process_clienthello.c @@ -280,6 +280,12 @@ USHORT no_extension = NX_FALSE; length += session_id_length; } + /* GHSA-5vrv-8j5h-h6h6 2504xx */ + if ((length + 1) >= message_length) + { + return(NX_SECURE_TLS_INCORRECT_MESSAGE_LENGTH); + } + /* Negotiate the ciphersuite we want to use. */ ciphersuite_list_length = (USHORT)((packet_buffer[length] << 8) + packet_buffer[length + 1]); length += 2; @@ -294,6 +300,12 @@ USHORT no_extension = NX_FALSE; length += ciphersuite_list_length; + /* GHSA-5vrv-8j5h-h6h6 2504xx */ + if (length >= message_length) + { + return(NX_SECURE_TLS_INCORRECT_MESSAGE_LENGTH); + } + /* Compression methods length - one byte. For now we only support the NULL method. */ compression_methods_length = packet_buffer[length]; length++; -- cgit v1.3.1