Skip to content

release 0.6.2.6

Choose a tag to compare

@zandbelt zandbelt released this 02 Jun 14:26
· 62 commits to version-0.6.2.x since this release

Security

  • AES-CBC-HMAC JWE encryption must use a random content-encryption key instead of an all-zero content-encryption key, see advisory GHSA-f6wf-pqg3-6wqq

Bugfixes

  • Enforce the RFC 7518 minimum HMAC key length (key >= hash size) for JWS sign/verify
    this means that e.g. symmetric keys for HS256 must be larger than 32 characters now, etc.
  • Additional hardening from a security audit of jwe.c / jwk.c / jws.c:
    • Fix EVP_CIPHER_CTX leak in AES-CBC content encryption on authentication-tag failure
    • Avoid NULL dereference of the optional cjose_err in ECDH-ES key decryption
    • Use a constant-time comparison for the multi-recipient CEK consistency check
    • Cleanse private key material (RSA/EC/oct) on JWK import and export, and fix a leak of the
      base64url buffer in EC private-key export
    • Check the ephemeral-key allocation in ECDH key derivation
    • Use integer arithmetic (instead of floating-point) for the base64url length check on
      imported JWK fields
    • Harden JWS EC signature reconstruction against allocation failures (NULL checks on
      ECDSA_SIG_new and BN_new)

The RPM packages below are signed with the following RSA PGP key:

-----BEGIN PGP PUBLIC KEY BLOCK-----

mQENBGh53lgBCADCyoOkfnE5h5rBLlf02oFpI/z2vUXK5W4T56xnNPu0/iIOxbBk
YX9rSypZFhfjv28lhGgelWEg28Ab/Yxs6l0obCgDEuFUDQ5Dv+N+YSMy67vtLwYW
9LM5p9fMN9bXOa62PwvtzRzh+xRyRBcIfMacGJC+SqUK6QhzC0lNwCsr1OaWjzon
mkaodwrloNMxEZVvFn63PvuQDZ3wwQty+0XpYiiChMssGBn6nmPDQJ7pDtQDkhfD
Z5FKY6K7AQJ4fneiVCLGngPBwTXBGcfWa+Y0HCS2ghQwDO6jYXd5GjowVDTjfMK3
QJ3e26Ox9X3V0Fl04R1i5EthEkAWGfy1lksvABEBAAG0HU9wZW5JREMgPHN1cHBv
cnRAb3BlbmlkYy5jb20+iQFRBBMBCgA7FiEEFdjWJA1IGDkAITSxnyZY1L0OSOMF
Amh53lgCGwMFCwkIBwICIgIGFQoJCAsCBBYCAwECHgcCF4AACgkQnyZY1L0OSONG
Jgf+II0wG96R0g28Kp+R4AYzSdX0CEqr6OhwHHw4cFpLsHxZNhojo7I4OnLKEdfc
lFl37rE+hG3QpzD/b4S/fpPjd4hcLkguBQxtdxqZZVAIT8HWbveHRkI8MNnjOPwv
Hy6jBncMs1IT/URV2si/Q34+PLo8tvo/lXNa16svVl2DoYXO8MCszgCE1bx055EF
XPh4Teu5Y4OLHECSicMxrmN746dAD121zy4bLLx9mZ0erhLjvkj1vkFmlHFKyvwY
/pbSqXs9hW/wweW1oQ/xEIJWWS71PeoutUBjr0WC4sILnR5PBPZplgNh297Qex6g
qaW3io0tCH9KxU1tXYn/iL/hbQ==
=mlOy
-----END PGP PUBLIC KEY BLOCK-----