mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 11:10:54 +03:00
fix(esp_tee): guard calloc overflow and attestation leak
This commit is contained in:
@@ -1,5 +1,5 @@
|
||||
/*
|
||||
* SPDX-FileCopyrightText: 2024-2025 Espressif Systems (Shanghai) CO LTD
|
||||
* SPDX-FileCopyrightText: 2024-2026 Espressif Systems (Shanghai) CO LTD
|
||||
*
|
||||
* SPDX-License-Identifier: Apache-2.0
|
||||
*/
|
||||
@@ -302,6 +302,11 @@ esp_err_t esp_att_utils_ecdsa_get_sign(const esp_att_ecdsa_keypair_t *keypair, c
|
||||
return ESP_ERR_INVALID_SIZE;
|
||||
}
|
||||
|
||||
/* Initialise the out-params up front so the error path at 'exit' can free them safely even
|
||||
* when we bail out (e.g. signature generation fails) before they are allocated. */
|
||||
*sign_r_hexstr = NULL;
|
||||
*sign_s_hexstr = NULL;
|
||||
|
||||
esp_err_t err = ESP_FAIL;
|
||||
|
||||
unsigned char sign_r[SECP256R1_ECDSA_KEY_LEN] = {0}, sign_s[SECP256R1_ECDSA_KEY_LEN] = {0};
|
||||
@@ -340,5 +345,12 @@ esp_err_t esp_att_utils_ecdsa_get_sign(const esp_att_ecdsa_keypair_t *keypair, c
|
||||
err = ESP_OK;
|
||||
|
||||
exit:
|
||||
if (err != ESP_OK) {
|
||||
/* free(NULL) is a no-op, so this is safe whether or not the buffers were allocated. */
|
||||
free(*sign_r_hexstr);
|
||||
*sign_r_hexstr = NULL;
|
||||
free(*sign_s_hexstr);
|
||||
*sign_s_hexstr = NULL;
|
||||
}
|
||||
return err;
|
||||
}
|
||||
|
||||
@@ -107,7 +107,10 @@ void *esp_tee_heap_malloc(size_t size)
|
||||
|
||||
void *esp_tee_heap_calloc(size_t n, size_t size)
|
||||
{
|
||||
size_t reg_size = n * size;
|
||||
size_t reg_size;
|
||||
if (__builtin_mul_overflow(n, size, ®_size)) {
|
||||
return NULL;
|
||||
}
|
||||
void *ptr = esp_tee_heap_malloc(reg_size);
|
||||
if (ptr != NULL) {
|
||||
memset(ptr, 0x00, reg_size);
|
||||
@@ -241,7 +244,10 @@ void *heap_caps_aligned_alloc(size_t alignment, size_t size, uint32_t caps)
|
||||
void *heap_caps_aligned_calloc(size_t alignment, size_t n, size_t size, uint32_t caps)
|
||||
{
|
||||
(void) caps;
|
||||
uint32_t reg_size = n * size;
|
||||
size_t reg_size;
|
||||
if (__builtin_mul_overflow(n, size, ®_size)) {
|
||||
return NULL;
|
||||
}
|
||||
|
||||
void *ptr = esp_tee_heap_aligned_alloc(reg_size, alignment);
|
||||
if (ptr != NULL) {
|
||||
|
||||
@@ -582,6 +582,10 @@ int esp_aes_gcm_finish( esp_gcm_context *ctx,
|
||||
uint8_t len_block[AES_BLOCK_BYTES] = {0};
|
||||
uint8_t stream[AES_BLOCK_BYTES] = {0};
|
||||
|
||||
(void)output;
|
||||
(void)output_size;
|
||||
*output_length = 0;
|
||||
|
||||
if ( tag_len > 16 || tag_len < 4 ) {
|
||||
return ( MBEDTLS_ERR_GCM_BAD_INPUT );
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user