Ankur Tyagi d0e8fba3a1 wolfssl: ptach CVE-2026-3229
Details: https://nvd.nist.gov/vuln/detail/CVE-2026-3229

Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
2026-04-21 08:57:47 +05:30

43 lines
1.5 KiB
Diff

From 62ab2c90ac6ad82a7586224096a73f84beac64c3 Mon Sep 17 00:00:00 2001
From: Eric Blankenhorn <eric@wolfssl.com>
Date: Tue, 24 Feb 2026 11:17:42 -0600
Subject: [PATCH] Fix from review
(cherry picked from commit 8f787909da890e5830a9a6f73d3c4ff0d9bd7da9)
CVE: CVE-2026-3229
Upstream-Status: Backport [https://github.com/wolfSSL/wolfssl/commit/8f787909da890e5830a9a6f73d3c4ff0d9bd7da9]
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
---
src/ssl_load.c | 15 +++++++++------
1 file changed, 9 insertions(+), 6 deletions(-)
diff --git a/src/ssl_load.c b/src/ssl_load.c
index 54e1a3095..8533d9a12 100644
--- a/src/ssl_load.c
+++ b/src/ssl_load.c
@@ -4777,14 +4777,17 @@ static int wolfssl_add_to_chain(DerBuffer** chain, int weOwn, const byte* cert,
if ((len > WOLFSSL_MAX_32BIT - CERT_HEADER_SZ) ||
(certSz > WOLFSSL_MAX_32BIT - CERT_HEADER_SZ - len)) {
WOLFSSL_MSG("wolfssl_add_to_chain overflow");
- return 0;
- }
- /* Allocate DER buffer big enough to hold old and new certificates. */
- ret = AllocDer(&newChain, len + CERT_HEADER_SZ + certSz, CERT_TYPE, heap);
- if (ret != 0) {
- WOLFSSL_MSG("AllocDer error");
res = 0;
}
+ if (res == 1) {
+ /* Allocate DER buffer big enough to hold old and new certificates. */
+ ret = AllocDer(&newChain, len + CERT_HEADER_SZ + certSz, CERT_TYPE,
+ heap);
+ if (ret != 0) {
+ WOLFSSL_MSG("AllocDer error");
+ res = 0;
+ }
+ }
if (res == 1) {
if (oldChain != NULL) {