From 1fc6094b144c2d3a47dfce89a15708dae7857e7e Mon Sep 17 00:00:00 2001 From: Ashish Sharma Date: Fri, 26 Jun 2026 18:41:16 +0800 Subject: [PATCH] fix(hal): clamp tag_len in aes_hal_gcm_read_tag to prevent OOB --- components/hal/aes_hal.c | 7 ++++++- 1 file changed, 6 insertions(+), 1 deletion(-) diff --git a/components/hal/aes_hal.c b/components/hal/aes_hal.c index f70ed1b9875..a8358d0a59f 100644 --- a/components/hal/aes_hal.c +++ b/components/hal/aes_hal.c @@ -1,5 +1,5 @@ /* - * SPDX-FileCopyrightText: 2020-2024 Espressif Systems (Shanghai) CO LTD + * SPDX-FileCopyrightText: 2020-2026 Espressif Systems (Shanghai) CO LTD * * SPDX-License-Identifier: Apache-2.0 */ @@ -126,6 +126,11 @@ void aes_hal_gcm_read_tag(uint8_t *tag, size_t tag_len) { uint8_t tag_res[TAG_BYTES]; aes_ll_gcm_read_tag(tag_res); + /* The GCM tag is at most TAG_BYTES (16). Clamp the caller-supplied length so an oversized + * tag_len cannot over-read tag_res or over-write the caller's tag buffer (CWE-125). */ + if (tag_len > TAG_BYTES) { + tag_len = TAG_BYTES; + } memcpy(tag, tag_res, tag_len); }