mirror of
https://github.com/espressif/esp-idf.git
synced 2026-10-02 11:10:54 +03:00
fix(esp_tee): fix DS-lock leak, intr-matrix OOB, calloc overflow, attestation leak
This commit is contained in:
@@ -1,5 +1,5 @@
|
|||||||
/*
|
/*
|
||||||
* SPDX-FileCopyrightText: 2024-2025 Espressif Systems (Shanghai) CO LTD
|
* SPDX-FileCopyrightText: 2024-2026 Espressif Systems (Shanghai) CO LTD
|
||||||
*
|
*
|
||||||
* SPDX-License-Identifier: Apache-2.0
|
* SPDX-License-Identifier: Apache-2.0
|
||||||
*/
|
*/
|
||||||
@@ -246,6 +246,11 @@ esp_err_t esp_att_utils_ecdsa_get_sign(const esp_att_ecdsa_keypair_t *keypair, c
|
|||||||
return ESP_ERR_INVALID_SIZE;
|
return ESP_ERR_INVALID_SIZE;
|
||||||
}
|
}
|
||||||
|
|
||||||
|
/* Initialise the out-params up front so the error path at 'exit' can free them safely even
|
||||||
|
* when we bail out (e.g. signature generation fails) before they are allocated. */
|
||||||
|
*sign_r_hexstr = NULL;
|
||||||
|
*sign_s_hexstr = NULL;
|
||||||
|
|
||||||
esp_err_t err = ESP_FAIL;
|
esp_err_t err = ESP_FAIL;
|
||||||
|
|
||||||
unsigned char sign_r[SECP256R1_ECDSA_KEY_LEN] = {0}, sign_s[SECP256R1_ECDSA_KEY_LEN] = {0};
|
unsigned char sign_r[SECP256R1_ECDSA_KEY_LEN] = {0}, sign_s[SECP256R1_ECDSA_KEY_LEN] = {0};
|
||||||
@@ -284,5 +289,12 @@ esp_err_t esp_att_utils_ecdsa_get_sign(const esp_att_ecdsa_keypair_t *keypair, c
|
|||||||
err = ESP_OK;
|
err = ESP_OK;
|
||||||
|
|
||||||
exit:
|
exit:
|
||||||
|
if (err != ESP_OK) {
|
||||||
|
/* free(NULL) is a no-op, so this is safe whether or not the buffers were allocated. */
|
||||||
|
free(*sign_r_hexstr);
|
||||||
|
*sign_r_hexstr = NULL;
|
||||||
|
free(*sign_s_hexstr);
|
||||||
|
*sign_s_hexstr = NULL;
|
||||||
|
}
|
||||||
return err;
|
return err;
|
||||||
}
|
}
|
||||||
|
|||||||
@@ -107,7 +107,10 @@ void *esp_tee_heap_malloc(size_t size)
|
|||||||
|
|
||||||
void *esp_tee_heap_calloc(size_t n, size_t size)
|
void *esp_tee_heap_calloc(size_t n, size_t size)
|
||||||
{
|
{
|
||||||
size_t reg_size = n * size;
|
size_t reg_size;
|
||||||
|
if (__builtin_mul_overflow(n, size, ®_size)) {
|
||||||
|
return NULL;
|
||||||
|
}
|
||||||
void *ptr = esp_tee_heap_malloc(reg_size);
|
void *ptr = esp_tee_heap_malloc(reg_size);
|
||||||
if (ptr != NULL) {
|
if (ptr != NULL) {
|
||||||
memset(ptr, 0x00, reg_size);
|
memset(ptr, 0x00, reg_size);
|
||||||
@@ -239,7 +242,10 @@ void *heap_caps_aligned_alloc(size_t alignment, size_t size, uint32_t caps)
|
|||||||
void *heap_caps_aligned_calloc(size_t alignment, size_t n, size_t size, uint32_t caps)
|
void *heap_caps_aligned_calloc(size_t alignment, size_t n, size_t size, uint32_t caps)
|
||||||
{
|
{
|
||||||
(void) caps;
|
(void) caps;
|
||||||
uint32_t reg_size = n * size;
|
size_t reg_size;
|
||||||
|
if (__builtin_mul_overflow(n, size, ®_size)) {
|
||||||
|
return NULL;
|
||||||
|
}
|
||||||
|
|
||||||
void *ptr = esp_tee_heap_aligned_alloc(reg_size, alignment);
|
void *ptr = esp_tee_heap_aligned_alloc(reg_size, alignment);
|
||||||
if (ptr != NULL) {
|
if (ptr != NULL) {
|
||||||
|
|||||||
@@ -533,6 +533,10 @@ int esp_aes_gcm_finish( esp_gcm_context *ctx,
|
|||||||
uint8_t len_block[AES_BLOCK_BYTES] = {0};
|
uint8_t len_block[AES_BLOCK_BYTES] = {0};
|
||||||
uint8_t stream[AES_BLOCK_BYTES] = {0};
|
uint8_t stream[AES_BLOCK_BYTES] = {0};
|
||||||
|
|
||||||
|
(void)output;
|
||||||
|
(void)output_size;
|
||||||
|
*output_length = 0;
|
||||||
|
|
||||||
if ( tag_len > 16 || tag_len < 4 ) {
|
if ( tag_len > 16 || tag_len < 4 ) {
|
||||||
return ( PSA_ERROR_INVALID_ARGUMENT );
|
return ( PSA_ERROR_INVALID_ARGUMENT );
|
||||||
}
|
}
|
||||||
|
|||||||
Reference in New Issue
Block a user