mirror of
git://git.openembedded.org/meta-openembedded
synced 2026-10-01 22:55:55 +00:00
Details: https://nvd.nist.gov/vuln/detail/CVE-2026-3229 Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
43 lines
1.5 KiB
Diff
43 lines
1.5 KiB
Diff
From 62ab2c90ac6ad82a7586224096a73f84beac64c3 Mon Sep 17 00:00:00 2001
|
|
From: Eric Blankenhorn <eric@wolfssl.com>
|
|
Date: Tue, 24 Feb 2026 11:17:42 -0600
|
|
Subject: [PATCH] Fix from review
|
|
|
|
(cherry picked from commit 8f787909da890e5830a9a6f73d3c4ff0d9bd7da9)
|
|
|
|
CVE: CVE-2026-3229
|
|
Upstream-Status: Backport [https://github.com/wolfSSL/wolfssl/commit/8f787909da890e5830a9a6f73d3c4ff0d9bd7da9]
|
|
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
|
|
---
|
|
src/ssl_load.c | 15 +++++++++------
|
|
1 file changed, 9 insertions(+), 6 deletions(-)
|
|
|
|
diff --git a/src/ssl_load.c b/src/ssl_load.c
|
|
index 54e1a3095..8533d9a12 100644
|
|
--- a/src/ssl_load.c
|
|
+++ b/src/ssl_load.c
|
|
@@ -4777,14 +4777,17 @@ static int wolfssl_add_to_chain(DerBuffer** chain, int weOwn, const byte* cert,
|
|
if ((len > WOLFSSL_MAX_32BIT - CERT_HEADER_SZ) ||
|
|
(certSz > WOLFSSL_MAX_32BIT - CERT_HEADER_SZ - len)) {
|
|
WOLFSSL_MSG("wolfssl_add_to_chain overflow");
|
|
- return 0;
|
|
- }
|
|
- /* Allocate DER buffer big enough to hold old and new certificates. */
|
|
- ret = AllocDer(&newChain, len + CERT_HEADER_SZ + certSz, CERT_TYPE, heap);
|
|
- if (ret != 0) {
|
|
- WOLFSSL_MSG("AllocDer error");
|
|
res = 0;
|
|
}
|
|
+ if (res == 1) {
|
|
+ /* Allocate DER buffer big enough to hold old and new certificates. */
|
|
+ ret = AllocDer(&newChain, len + CERT_HEADER_SZ + certSz, CERT_TYPE,
|
|
+ heap);
|
|
+ if (ret != 0) {
|
|
+ WOLFSSL_MSG("AllocDer error");
|
|
+ res = 0;
|
|
+ }
|
|
+ }
|
|
|
|
if (res == 1) {
|
|
if (oldChain != NULL) {
|