Skip to content

Commit 75360af

Browse files
nhormanjogme
authored andcommitted
Fix unbounded cert cache growth in cmp
If a remote user sends cmp messages to a server with a list of extraCerts and the message is rejected, the extraCerts from the message remain in the server contexts untrusted certificate stack. This exposes servers with long lived ctx objects to denial of service attacks in which an attacker sends messages intending to be rejected with a large list of additional cerificated repeatedly, forcing the server to store them indefinately. Fix it by rolling back the added extra certs if the message is rejected, using the same method we do when the context is configured to not do caching at all. Fixes openssl/srt#224 Fixes CVE-2026-63074 Reviewed-by: Milan Broz <mbroz@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> Merge-date: Mon Aug 24 12:42:35 2026
1 parent 2501a37 commit 75360af

1 file changed

Lines changed: 7 additions & 2 deletions

File tree

‎crypto/cmp/cmp_vfy.c‎

Lines changed: 7 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -778,8 +778,13 @@ int ossl_cmp_msg_check_update(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg,
778778
res = 1; /* support more aggressive fuzzing by letting invalid msg pass */
779779
#endif
780780

781-
/* remove extraCerts again if not caching */
782-
if (ctx->noCacheExtraCerts)
781+
/*
782+
* remove extraCerts again if not caching
783+
* or if we failed validation above, lest a remote user
784+
* starts sending us lots of certificates in invalid messages
785+
* leading to a DOS from unbounded certificate stack growth
786+
*/
787+
if (ctx->noCacheExtraCerts || res != 1)
783788
while (num_added-- > 0)
784789
X509_free(sk_X509_shift(ctx->untrusted));
785790

0 commit comments

Comments
 (0)