Merge pull request #1647 from bjwtaylor/oob-key-exchange-restricted-3.6

Add fix for OOB key exchange error 3.6
This commit is contained in:
Ronald Cron
2026-06-15 22:42:22 +02:00
committed by GitHub
2 changed files with 6 additions and 0 deletions
@@ -0,0 +1,4 @@
Security
* Fix an out-of-bounds read when parsing TLS 1.2 ECJPAKE ServerKeyExchange
messages. Reported-by Biniam Demissie.
CVE-2026-50588
+2
View File
@@ -2325,6 +2325,8 @@ start_processing:
* However since we only support secp256r1 for now, we check only
* that TLS ID here
*/
MBEDTLS_SSL_CHK_BUF_READ_PTR(p, end, 3);
uint16_t read_tls_id = MBEDTLS_GET_UINT16_BE(p, 1);
uint16_t exp_tls_id = mbedtls_ssl_get_tls_id_from_ecp_group_id(
MBEDTLS_ECP_DP_SECP256R1);