From 25f5e205cdded2e52b9866ff88b533a03aa01354 Mon Sep 17 00:00:00 2001 From: Ashish Sharma Date: Mon, 6 Jul 2026 17:44:14 +0800 Subject: [PATCH] fix(mbedtls): bound *iv_off in DMA esp_aes_crypt_ofb to prevent OOB read --- components/mbedtls/port/aes/dma/esp_aes.c | 9 +++++++++ 1 file changed, 9 insertions(+) diff --git a/components/mbedtls/port/aes/dma/esp_aes.c b/components/mbedtls/port/aes/dma/esp_aes.c index fcd4ed8a203..0bd75f6bc15 100644 --- a/components/mbedtls/port/aes/dma/esp_aes.c +++ b/components/mbedtls/port/aes/dma/esp_aes.c @@ -436,6 +436,15 @@ int esp_aes_crypt_ofb(esp_aes_context *ctx, n = *iv_off; + /* iv[] is a fixed AES_BLOCK_BYTES buffer and n indexes it directly (before the modulo update), + * so a caller-supplied *iv_off >= AES_BLOCK_BYTES -- attacker-controlled via the TEE secure + * service -- is an out-of-bounds read of iv[] in TEE context (CWE-125), leaking adjacent + * memory into the output. Bound it here, matching the block esp_aes_crypt_ofb() variant. */ + if (n >= AES_BLOCK_BYTES) { + ESP_LOGE(TAG, "IV offset out of bounds"); + return MBEDTLS_ERR_AES_BAD_INPUT_DATA; + } + /* If there is an offset then use the output of the previous AES block (the updated IV) to calculate the new output */ while (n > 0 && length > 0) {