pkcs11-helper icon indicating copy to clipboard operation
pkcs11-helper copied to clipboard

util: fix deserialize buffer overflow

Open alonbl opened this issue 1 month ago • 2 comments

Missing check for source file increment.

Reported-by: Aarnav Bos [email protected]

alonbl avatar Nov 06 '25 18:11 alonbl

@selvanair thank you so much for the review, I've modified the implementation to use macros, I hope now all is ok.

alonbl avatar Nov 07 '25 19:11 alonbl

Looks good to me if returning a wrong value of *max is okay in case of error. Let's see whether the fuzzer can still crash it!

selvanair avatar Nov 07 '25 21:11 selvanair

@selvanair @alonbl the fix also looks good from the fuzzing side!

R9295 avatar Nov 10 '25 08:11 R9295

Thank you all!

alonbl avatar Nov 10 '25 14:11 alonbl