Repository navigation
Fix sign, verify and MAC parameter checks - #240
Open
aidangarske wants to merge 150 commits into
Open
aidangarske wants to merge 150 commits into
aidangarske wants to merge 150 commits into
Conversation
18 tasks
aidangarske
force-pushed
the
fenrir-fixes-10392-8674
branch
2 times, most recently
from
October 9, 2026 02:00
35dd82c to
3389bd5
Compare
aidangarske
force-pushed
the
fenrir-fixes-10392-8674
branch
from
October 10, 2026 03:20
3389bd5 to
b040fc3
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
F-10392- e5178fb - New CheckPssMechParams in C_SignInit and C_VerifyInit rejects a hash algorithm that differs from the digest of the CKM_SHA*_RSA_PKCS_PSS mechanism. Raw CKM_RSA_PKCS_PSS is unchanged.F-8674- 49f1100 - CKM_AES_CMAC in C_SignInit and C_VerifyInit now produces and checks a full 16-byte tag instead of half.F-13817- fc89e1e - C_SignFinal for CKM_TLS_MAC now keeps the buffered data and the operation active when it returns CKR_BUFFER_TOO_SMALL.F-13247- 0e4d2c7 - C_VerifyUpdate and C_VerifyFinal now support CKM_TLS_MAC, C_Verify refuses to finish a multi-part verify, and session data is freed at close and cleared in WP11_TLS_MAC_init.F-8655- 7b29f3a - C_Verify for ECDSA now returns CKR_SIGNATURE_LEN_RANGE when the signature is not the expected length.F-5872- 408c2c3 - CKM_AES_CMAC_GENERAL now range checks the CK_ULONG MAC length before casting it to word32.F-4802- 676db4a - WP11_TLS_MAC_init now rejects a MAC length that does not fit in 32 bits.F-4960- 11a9302 - WP11_Session_SetPssParams now takes a CK_ULONG salt length and rejects values above RSA_MAX_SIZE/8.F-5873- c5437db - WP11_Hmac_Init now compares the full CK_ULONG length parameter against the digest size.F-6665- 2595e44 - WP11_Rsa_Verify for CKM_RSA_X_509 now checks in constant time that the leading bytes of the recovered block are zero.F-10401- 8bb37c4 - WP11_Rsa_Sign now returns BUFFER_E when the key is larger than its RSA_MAX_SIZE stack buffer.F-10402- 9198e92 - WP11_Rsa_Verify now rejects a key larger than the recovery buffer before calling wc_RsaDirect.F-6962- 9648af7 - WP11_Rsa_Sign now zeroizes the padded input buffer with wc_ForceZero before returning.F-8639- b733a99 - Without WC_RSA_DIRECT, the CKM_RSA_X_509 sign, verify and verify-recover init paths return CKR_MECHANISM_INVALID and the mechanism info no longer lists those flags.F-5075- 3389bd5 - The MAXQ10xx C_SignInit path for key handle 0 now requires a user login and returns CKR_USER_NOT_LOGGED_IN otherwise.