From 2bd2b788cf82437d1d238bbdadbd26fa652532aa Mon Sep 17 00:00:00 2001 From: Jonathan Winzig Date: Tue, 9 Jan 2024 15:19:42 +0100 Subject: [PATCH 1/7] Add tests for Issue #8687 Signed-off-by: Jonathan Winzig --- tests/suites/test_suite_x509write.data | 6 ++++++ tests/suites/test_suite_x509write.function | 21 +++++++++++++++++++++ 2 files changed, 27 insertions(+) diff --git a/tests/suites/test_suite_x509write.data b/tests/suites/test_suite_x509write.data index 28cef301c..730e76e71 100644 --- a/tests/suites/test_suite_x509write.data +++ b/tests/suites/test_suite_x509write.data @@ -265,3 +265,9 @@ mbedtls_x509_string_to_names:"C=NL, 2.5.4.10.234.532=#0C084F6666737061726B, OU=P Check max serial length x509_set_serial_check: + +Check max extension length (Max-1) +x509_set_extension_length_check:0xFFFFFFFE + +Check max extension length (Max) +x509_set_extension_length_check:0xFFFFFFFF \ No newline at end of file diff --git a/tests/suites/test_suite_x509write.function b/tests/suites/test_suite_x509write.function index b59fd48f3..7690dc049 100644 --- a/tests/suites/test_suite_x509write.function +++ b/tests/suites/test_suite_x509write.function @@ -752,3 +752,24 @@ exit: USE_PSA_DONE(); } /* END_CASE */ + +/* BEGIN_CASE */ +void x509_set_extension_length_check(int val_len) +{ + int ret = 0; + + mbedtls_x509write_csr ctx; + mbedtls_x509write_csr_init(&ctx); + + unsigned char buf[EXT_KEY_USAGE_TMP_BUF_MAX_LENGTH] = { 0 }; + unsigned char *p = buf + sizeof(buf); + + ret = mbedtls_x509_set_extension(&(ctx.MBEDTLS_PRIVATE(extensions)), + MBEDTLS_OID_EXTENDED_KEY_USAGE, + MBEDTLS_OID_SIZE(MBEDTLS_OID_EXTENDED_KEY_USAGE), + 0, + p, + val_len); + TEST_ASSERT(ret == MBEDTLS_ERR_X509_BAD_INPUT_DATA || ret == MBEDTLS_ERR_X509_ALLOC_FAILED); +} +/* END_CASE */ From 05c722bfd03712b5fbea0dc3087244be10425935 Mon Sep 17 00:00:00 2001 From: Jonathan Winzig Date: Tue, 9 Jan 2024 15:20:03 +0100 Subject: [PATCH 2/7] Fix Issue #8687 Signed-off-by: Jonathan Winzig --- library/x509_create.c | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/library/x509_create.c b/library/x509_create.c index 8f31c3bea..c761a8c45 100644 --- a/library/x509_create.c +++ b/library/x509_create.c @@ -382,6 +382,10 @@ int mbedtls_x509_set_extension(mbedtls_asn1_named_data **head, const char *oid, { mbedtls_asn1_named_data *cur; + if (0xFFFFFFFF == (uint32_t) val_len) { + return MBEDTLS_ERR_X509_BAD_INPUT_DATA; + } + if ((cur = mbedtls_asn1_store_named_data(head, oid, oid_len, NULL, val_len + 1)) == NULL) { return MBEDTLS_ERR_X509_ALLOC_FAILED; From 5caf20ea80b46edbad29448d169e694659968cd1 Mon Sep 17 00:00:00 2001 From: Jonathan Winzig Date: Tue, 9 Jan 2024 16:41:10 +0100 Subject: [PATCH 3/7] Update fix to be more platform-independent Co-authored-by: David Horstmann Signed-off-by: Jonathan Winzig --- library/x509_create.c | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/library/x509_create.c b/library/x509_create.c index c761a8c45..f7a17e712 100644 --- a/library/x509_create.c +++ b/library/x509_create.c @@ -382,7 +382,7 @@ int mbedtls_x509_set_extension(mbedtls_asn1_named_data **head, const char *oid, { mbedtls_asn1_named_data *cur; - if (0xFFFFFFFF == (uint32_t) val_len) { + if (val_len > (SIZE_MAX - 1)) { return MBEDTLS_ERR_X509_BAD_INPUT_DATA; } From c5e77bf4e490d6a84311916572b6e9c8320ffc06 Mon Sep 17 00:00:00 2001 From: Jonathan Winzig Date: Tue, 9 Jan 2024 16:47:12 +0100 Subject: [PATCH 4/7] Add missing newline at the end of test_suite_x509write.data Signed-off-by: Jonathan Winzig --- tests/suites/test_suite_x509write.data | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tests/suites/test_suite_x509write.data b/tests/suites/test_suite_x509write.data index 730e76e71..f46d19d58 100644 --- a/tests/suites/test_suite_x509write.data +++ b/tests/suites/test_suite_x509write.data @@ -270,4 +270,4 @@ Check max extension length (Max-1) x509_set_extension_length_check:0xFFFFFFFE Check max extension length (Max) -x509_set_extension_length_check:0xFFFFFFFF \ No newline at end of file +x509_set_extension_length_check:0xFFFFFFFF From a72454bc16701603a93b05c60b4339341703a2c6 Mon Sep 17 00:00:00 2001 From: Jonathan Winzig Date: Tue, 9 Jan 2024 17:39:42 +0100 Subject: [PATCH 5/7] Update test-data to use SIZE_MAX Co-authored-by: David Horstmann Signed-off-by: Jonathan Winzig --- tests/suites/test_suite_x509write.data | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tests/suites/test_suite_x509write.data b/tests/suites/test_suite_x509write.data index f46d19d58..869ea7f59 100644 --- a/tests/suites/test_suite_x509write.data +++ b/tests/suites/test_suite_x509write.data @@ -270,4 +270,4 @@ Check max extension length (Max-1) x509_set_extension_length_check:0xFFFFFFFE Check max extension length (Max) -x509_set_extension_length_check:0xFFFFFFFF +x509_set_extension_length_check:SIZE_MAX From 6c9779fabbafa060e130728bdb899f0cf9d7d08a Mon Sep 17 00:00:00 2001 From: Jonathan Winzig Date: Tue, 9 Jan 2024 17:47:10 +0100 Subject: [PATCH 6/7] Remove unneeded testcase Signed-off-by: Jonathan Winzig --- tests/suites/test_suite_x509write.data | 7 ++----- tests/suites/test_suite_x509write.function | 6 +++--- 2 files changed, 5 insertions(+), 8 deletions(-) diff --git a/tests/suites/test_suite_x509write.data b/tests/suites/test_suite_x509write.data index 869ea7f59..5c6a9032d 100644 --- a/tests/suites/test_suite_x509write.data +++ b/tests/suites/test_suite_x509write.data @@ -266,8 +266,5 @@ mbedtls_x509_string_to_names:"C=NL, 2.5.4.10.234.532=#0C084F6666737061726B, OU=P Check max serial length x509_set_serial_check: -Check max extension length (Max-1) -x509_set_extension_length_check:0xFFFFFFFE - -Check max extension length (Max) -x509_set_extension_length_check:SIZE_MAX +Check max extension length +x509_set_extension_length_check: diff --git a/tests/suites/test_suite_x509write.function b/tests/suites/test_suite_x509write.function index 7690dc049..4c002f9ee 100644 --- a/tests/suites/test_suite_x509write.function +++ b/tests/suites/test_suite_x509write.function @@ -754,7 +754,7 @@ exit: /* END_CASE */ /* BEGIN_CASE */ -void x509_set_extension_length_check(int val_len) +void x509_set_extension_length_check() { int ret = 0; @@ -769,7 +769,7 @@ void x509_set_extension_length_check(int val_len) MBEDTLS_OID_SIZE(MBEDTLS_OID_EXTENDED_KEY_USAGE), 0, p, - val_len); - TEST_ASSERT(ret == MBEDTLS_ERR_X509_BAD_INPUT_DATA || ret == MBEDTLS_ERR_X509_ALLOC_FAILED); + SIZE_MAX); + TEST_ASSERT(MBEDTLS_ERR_X509_BAD_INPUT_DATA == ret); } /* END_CASE */ From 315c3ca9e55f74e58ae4a5be96c2ed890106c0dd Mon Sep 17 00:00:00 2001 From: Jonathan Winzig Date: Tue, 9 Jan 2024 18:31:11 +0100 Subject: [PATCH 7/7] Add required dependency to the testcase Co-authored-by: Paul Elliott <62069445+paul-elliott-arm@users.noreply.github.com> Signed-off-by: Jonathan Winzig --- tests/suites/test_suite_x509write.function | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/tests/suites/test_suite_x509write.function b/tests/suites/test_suite_x509write.function index 4c002f9ee..503d9764c 100644 --- a/tests/suites/test_suite_x509write.function +++ b/tests/suites/test_suite_x509write.function @@ -753,7 +753,7 @@ exit: } /* END_CASE */ -/* BEGIN_CASE */ +/* BEGIN_CASE depends_on:MBEDTLS_X509_CSR_WRITE_C */ void x509_set_extension_length_check() { int ret = 0;