Skip to content

Fix sign, verify and MAC parameter checks - #240

Open
aidangarske wants to merge 150 commits into
wolfSSL:masterfrom
aidangarske:fenrir-fixes-10392-8674
Open

aidangarske wants to merge 150 commits into
wolfSSL:masterfrom
aidangarske:fenrir-fixes-10392-8674

Conversation

@aidangarske

@aidangarske aidangarske commented Oct 8, 2026 •

Copy link
Copy Markdown
Member

F-10392 - e5178fb - New CheckPssMechParams in C_SignInit and C_VerifyInit rejects a hash algorithm that differs from the digest of the CKM_SHA*_RSA_PKCS_PSS mechanism. Raw CKM_RSA_PKCS_PSS is unchanged.

F-8674 - 49f1100 - CKM_AES_CMAC in C_SignInit and C_VerifyInit now produces and checks a full 16-byte tag instead of half.

F-13817 - fc89e1e - C_SignFinal for CKM_TLS_MAC now keeps the buffered data and the operation active when it returns CKR_BUFFER_TOO_SMALL.

F-13247 - 0e4d2c7 - C_VerifyUpdate and C_VerifyFinal now support CKM_TLS_MAC, C_Verify refuses to finish a multi-part verify, and session data is freed at close and cleared in WP11_TLS_MAC_init.

F-8655 - 7b29f3a - C_Verify for ECDSA now returns CKR_SIGNATURE_LEN_RANGE when the signature is not the expected length.

F-5872 - 408c2c3 - CKM_AES_CMAC_GENERAL now range checks the CK_ULONG MAC length before casting it to word32.

F-4802 - 676db4a - WP11_TLS_MAC_init now rejects a MAC length that does not fit in 32 bits.

F-4960 - 11a9302 - WP11_Session_SetPssParams now takes a CK_ULONG salt length and rejects values above RSA_MAX_SIZE/8.

F-5873 - c5437db - WP11_Hmac_Init now compares the full CK_ULONG length parameter against the digest size.

F-6665 - 2595e44 - WP11_Rsa_Verify for CKM_RSA_X_509 now checks in constant time that the leading bytes of the recovered block are zero.

F-10401 - 8bb37c4 - WP11_Rsa_Sign now returns BUFFER_E when the key is larger than its RSA_MAX_SIZE stack buffer.

F-10402 - 9198e92 - WP11_Rsa_Verify now rejects a key larger than the recovery buffer before calling wc_RsaDirect.

F-6962 - 9648af7 - WP11_Rsa_Sign now zeroizes the padded input buffer with wc_ForceZero before returning.

F-8639 - b733a99 - Without WC_RSA_DIRECT, the CKM_RSA_X_509 sign, verify and verify-recover init paths return CKR_MECHANISM_INVALID and the mechanism info no longer lists those flags.

F-5075 - 3389bd5 - The MAXQ10xx C_SignInit path for key handle 0 now requires a user login and returns CKR_USER_NOT_LOGGED_IN otherwise.

@aidangarske aidangarske self-assigned this Oct 8, 2026
Copilot AI balanced review requested due to automatic review settings October 8, 2026 22:10

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@aidangarske
aidangarske force-pushed the fenrir-fixes-10392-8674 branch 2 times, most recently from 35dd82c to 3389bd5 Compare October 9, 2026 02:00
@aidangarske aidangarske changed the title Fix sign, verify, and MAC parameter checks Fix sign, verify and MAC parameter checks Oct 9, 2026
@aidangarske
aidangarske force-pushed the fenrir-fixes-10392-8674 branch from 3389bd5 to b040fc3 Compare October 10, 2026 03:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants