Skip to content

Add bounds checks for MP integer size in SizeASN_Items#10051

Merged
douzzer merged 4 commits intowolfSSL:masterfrom
anhu:mp_int_bounds
May 1, 2026
Merged

Add bounds checks for MP integer size in SizeASN_Items#10051
douzzer merged 4 commits intowolfSSL:masterfrom
anhu:mp_int_bounds

Conversation

@anhu
Copy link
Copy Markdown
Member

@anhu anhu commented Mar 23, 2026

Fixes ZD 21401

@anhu anhu requested a review from wolfSSL-Bot March 23, 2026 20:18
@anhu anhu self-assigned this Mar 23, 2026
@dgarske
Copy link
Copy Markdown
Member

dgarske commented Mar 24, 2026

Jenkins retest this please -history lost

@anhu
Copy link
Copy Markdown
Member Author

anhu commented Mar 25, 2026

Jenkins retest this please.

Unable to get pull request trigger.

@anhu
Copy link
Copy Markdown
Member Author

anhu commented Mar 25, 2026

Jenkins retest this please

Build was aborted

@anhu
Copy link
Copy Markdown
Member Author

anhu commented Mar 26, 2026

jenkins retest this please

remote hung up.

@anhu
Copy link
Copy Markdown
Member Author

anhu commented Mar 26, 2026

jenkins retest this please

ABORTED

@anhu
Copy link
Copy Markdown
Member Author

anhu commented Mar 27, 2026

jenkins retest this please.

@anhu
Copy link
Copy Markdown
Member Author

anhu commented Mar 27, 2026

Jenkins retest this please.

1 similar comment
@anhu
Copy link
Copy Markdown
Member Author

anhu commented Mar 30, 2026

Jenkins retest this please.

@anhu anhu added the Not For This Release Not for release 5.9.1 label Apr 1, 2026
@anhu
Copy link
Copy Markdown
Member Author

anhu commented Apr 1, 2026

jenkins retest this please

Not found.

@anhu
Copy link
Copy Markdown
Member Author

anhu commented Apr 1, 2026

Jenkins retest this please.

@anhu
Copy link
Copy Markdown
Member Author

anhu commented Apr 8, 2026

jenkins retest this please.

@anhu anhu removed the Not For This Release Not for release 5.9.1 label Apr 8, 2026
@anhu
Copy link
Copy Markdown
Member Author

anhu commented Apr 8, 2026

jenkins retest this please.

Comment thread tests/api/test_rsa.c Outdated
Copy link
Copy Markdown
Member

@dgarske dgarske left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🐺 Skoll Code Review

Overall recommendation: APPROVE
Findings: 3 total — 3 posted, 0 skipped

Posted findings

  • [Medium] SetASN_Items MP path lacks matching bounds checkswolfcrypt/src/asn.c:1097-1099
  • [Medium] Test only covers USE_INTEGER_HEAP_MATH; tfm.c has same overflow patterntests/api/test_rsa.c:1161-1163
  • [Low] Unused variable derRet could use (void) cast or direct use in Expecttests/api/test_rsa.c:1254-1255

Review generated by Skoll via openclaw

Comment thread wolfcrypt/src/asn.c
Comment thread tests/api/test_rsa.c
Comment thread tests/api/test_rsa.c
@anhu
Copy link
Copy Markdown
Member Author

anhu commented Apr 10, 2026

jenkins retest this please

@github-actions
Copy link
Copy Markdown

MemBrowse Memory Report

No memory changes detected for:

@anhu
Copy link
Copy Markdown
Member Author

anhu commented Apr 17, 2026

jenkins retest this please

@anhu
Copy link
Copy Markdown
Member Author

anhu commented Apr 27, 2026

Jenkins retest this please

@anhu anhu assigned wolfSSL-Bot and unassigned anhu Apr 27, 2026
@anhu
Copy link
Copy Markdown
Member Author

anhu commented Apr 29, 2026

Good to go. @wolfSSL-Bot , please sqash and merge at will.

@douzzer douzzer merged commit 7b53303 into wolfSSL:master May 1, 2026
435 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants