Skip to content

Commit 205e3a5

Browse files
committed
pkcs12: Validate salt and keylength in PBMAC1
The keylength value must be present and we accept EVP_MAX_MD_SIZE at maximum. The salt ASN.1 type must be OCTET STRING. Fixes CVE-2025-11187 Reported by Stanislav Fort (Aisle Research) and Petr Simecek (Aisle Research). Reported independently also by Hamza (Metadust). Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com> Reviewed-by: Saša Nedvědický <sashan@openssl.org> Reviewed-by: Alicja Kario <hkario@redhat.com> MergeDate: Mon Jan 26 16:14:15 2026 (cherry picked from commit de157b8)
1 parent b865477 commit 205e3a5

1 file changed

Lines changed: 16 additions & 2 deletions

File tree

‎crypto/pkcs12/p12_mutl.c‎

Lines changed: 16 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -122,8 +122,6 @@ static int PBMAC1_PBKDF2_HMAC(OSSL_LIB_CTX *ctx, const char *propq,
122122
ERR_raise(ERR_LIB_PKCS12, ERR_R_UNSUPPORTED);
123123
goto err;
124124
}
125-
keylen = ASN1_INTEGER_get(pbkdf2_param->keylength);
126-
pbkdf2_salt = pbkdf2_param->salt->value.octet_string;
127125

128126
if (pbkdf2_param->prf == NULL) {
129127
kdf_hmac_nid = NID_hmacWithSHA1;
@@ -138,6 +136,22 @@ static int PBMAC1_PBKDF2_HMAC(OSSL_LIB_CTX *ctx, const char *propq,
138136
goto err;
139137
}
140138

139+
/* Validate salt is an OCTET STRING choice */
140+
if (pbkdf2_param->salt == NULL
141+
|| pbkdf2_param->salt->type != V_ASN1_OCTET_STRING) {
142+
ERR_raise(ERR_LIB_PKCS12, PKCS12_R_PARSE_ERROR);
143+
goto err;
144+
}
145+
pbkdf2_salt = pbkdf2_param->salt->value.octet_string;
146+
147+
/* RFC 9579 specifies missing key length as invalid */
148+
if (pbkdf2_param->keylength != NULL)
149+
keylen = ASN1_INTEGER_get(pbkdf2_param->keylength);
150+
if (keylen <= 0 || keylen > EVP_MAX_MD_SIZE) {
151+
ERR_raise(ERR_LIB_PKCS12, PKCS12_R_PARSE_ERROR);
152+
goto err;
153+
}
154+
141155
if (PKCS5_PBKDF2_HMAC(pass, passlen, pbkdf2_salt->data, pbkdf2_salt->length,
142156
ASN1_INTEGER_get(pbkdf2_param->iter), kdf_md, keylen, key)
143157
<= 0) {

0 commit comments

Comments
 (0)