CVSROOT:        /cvs
Module name:    src
Changes by:     [email protected]    2026/08/30 10:56:45

Modified files:
        lib/libcrypto/pkcs7: pk7_lib.c 

Log message:
PKCS7_stream: avoid out of bounds access

The inner content of SignedData is represented by a PKCS7 object, which
PKCS7_stream() assumes to be a plain data object and will thus access its
content via an ASN1_OCTET_STRING. This need not be the case after parsing.
In fact, the inner content type is essentially arbitrary.

If the inner content isn't one of the explicitly supported content types,
the fallback (via p7default_tt) will populate the union's d.other with an
ASN1_ANY which unravels to ASN1_TYPE_new() deep in the guts of tasn_dec,
allocating a 16-byte object on LP64 architectures. In that case, the
16-byte object is interpreted as an 24-byte ASN1_OCTET_STRING and if it
isn't NULL, the read+write to os->flags (a long at offset 16) is out of
bounds: os->flags | ASN1_STRING_FLAG_NDEF;

Add a check that the content is actually id-data before accessing the
d.data union member.

>From Acts1631

Reply via email to