Skip to content

Commit 7eb2e3e

Browse files
committed
CMP unexpected sender DN used as format string in ERR_raise_data()
ossl_cmp_msg_check_update() converts an unexpected CMP response sender DN with X509_NAME_oneline() and passes that peer-controlled string directly as the format argument to ERR_raise_data(). Printable percent characters survive the DN conversion, so a sender such as CN=%s%n reaches vsnprintf() as active format syntax without matching varargs. Fixes: CVE-2026-63073 Original patch by: Filipe Casal of Trail of Bits in collaboration with OpenAI Signed-off-by: Norbert Pocs <norbertp@openssl.org> Reviewed-by: Milan Broz <mbroz@openssl.org> Reviewed-by: Igor Ustinov <igus@openssl.foundation> Merge-date: Mon Aug 24 13:00:49 2026
1 parent dad836b commit 7eb2e3e

1 file changed

Lines changed: 1 addition & 1 deletion

File tree

‎crypto/cmp/cmp_vfy.c‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -757,7 +757,7 @@ int ossl_cmp_msg_check_update(OSSL_CMP_CTX *ctx, const OSSL_CMP_MSG *msg,
757757
"expected sender", expected_sender)) {
758758
str = X509_NAME_oneline(actual_sender, NULL, 0);
759759
ERR_raise_data(ERR_LIB_CMP, CMP_R_UNEXPECTED_SENDER,
760-
str != NULL ? str : "<unknown>");
760+
"%s", str != NULL ? str : "<unknown>");
761761
OPENSSL_free(str);
762762
return 0;
763763
}

0 commit comments

Comments
 (0)