On Wed, 2 Sep 2026 12:44:06 GMT, Timofei Fedotov <[email protected]> wrote:

>> Rfc2253Parser silently accepted an empty RDN (no attributeTypeAndValue pair) 
>> instead of
>> throwing InvalidNameException. Rdn.getType()/getValue() then indexed an empty
>> internal list, throwing an uncaught IndexOutOfBoundsException instead of the 
>> documented
>> exception.
>> 
>> Two independent entry points:
>> 
>> Rdn("") - the original fuzzer-found crash.
>> LdapName("cn=x,") / LdapName.add("") - a string with a trailing , or ;, 
>> which never goes
>> through Rdn(String) at all (LdapName builds the RDN directly via 
>> Rfc2253Parser).
>> 
>> Add one check, rdn.size() == 0, throw InvalidNameException, placed in
>> 
>> Rfc2253Parser.doParse(Rdn) - the single method both paths funnel through.
>> 
>> Also add a regression check that "cn=a,,cn=b" still throws as before.
>> 
>> 
>> 
>> 
>> ---------
>> - [x] I confirm that I make this contribution in accordance with the 
>> [OpenJDK Interim AI Policy](https://openjdk.org/legal/ai).
>
> Timofei Fedotov has updated the pull request incrementally with one 
> additional commit since the last revision:
> 
>   Add regression test

i've added the "csr" label to this issue as this proposal means an exception 
will be thrown for cases where it wasn't previously thrown. It's likely the 
current behavior dates from JDK 1.5 when the LDAP support was extended to we 
have t very cautious.

-------------

PR Comment: https://git.openjdk.org/jdk/pull/32648#issuecomment-5510655226

Reply via email to