Fix off-by-one s_client overflows#30731
Closed
mattcaswell wants to merge 1 commit into
Closed
Conversation
There are one byte buffer overflows possible in s_client's handling of STARTTLS in various protocols. If a server's response fills the entire buffer (16k) then we attempt to add a NUL terminator one byte off the end of the buffer. This was reported by Igor Morgenstern from AISLE to openssl-security and assessed by the security team as "bug or hardening only".
Member
Author
|
See also the backport in #30732 |
paulidale
approved these changes
Apr 9, 2026
npajkovsky
approved these changes
Apr 9, 2026
t8m
approved these changes
Apr 9, 2026
Collaborator
|
This pull request is ready to merge |
esyr
approved these changes
Apr 10, 2026
openssl-machine
pushed a commit
that referenced
this pull request
Apr 11, 2026
There are one byte buffer overflows possible in s_client's handling of STARTTLS in various protocols. If a server's response fills the entire buffer (16k) then we attempt to add a NUL terminator one byte off the end of the buffer. This was reported by Igor Morgenstern from AISLE to openssl-security and assessed by the security team as "bug or hardening only". Reviewed-by: Paul Dale <paul.dale@oracle.com> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org> Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> MergeDate: Sat Apr 11 16:16:24 2026 (Merged from #30731)
openssl-machine
pushed a commit
that referenced
this pull request
Apr 11, 2026
There are one byte buffer overflows possible in s_client's handling of STARTTLS in various protocols. If a server's response fills the entire buffer (16k) then we attempt to add a NUL terminator one byte off the end of the buffer. This was reported by Igor Morgenstern from AISLE to openssl-security and assessed by the security team as "bug or hardening only". Reviewed-by: Paul Dale <paul.dale@oracle.com> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org> Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> MergeDate: Sat Apr 11 16:25:52 2026 (Merged from #30731)
|
Thank you for your contribution. Merged into |
This was referenced Apr 13, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
There are one byte buffer overflows possible in s_client's handling of STARTTLS in various protocols. If a server's response fills the entire buffer (16k) then we attempt to add a NUL terminator one byte off the end of the buffer.
This was reported by Igor Morgenstern from AISLE to openssl-security and assessed by the security team as "bug or hardening only".