Skip to content

Commit a91e537

Browse files
igus68t8m
authored andcommitted
Avoid possible buffer overflow in buf2hex conversion
Fixes CVE-2026-31789 Reviewed-by: Saša Nedvědický <sashan@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> MergeDate: Mon Apr 6 19:41:24 2026
1 parent b7ae7a0 commit a91e537

1 file changed

Lines changed: 14 additions & 1 deletion

File tree

‎crypto/o_str.c‎

Lines changed: 14 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -236,6 +236,11 @@ static int buf2hexstr_sep(char *str, size_t str_n, size_t *strlength,
236236
int has_sep = (sep != CH_ZERO);
237237
size_t len = has_sep ? buflen * 3 : 1 + buflen * 2;
238238

239+
if (buflen > (has_sep ? SIZE_MAX / 3 : (SIZE_MAX - 1) / 2)) {
240+
ERR_raise(ERR_LIB_CRYPTO, CRYPTO_R_TOO_MANY_BYTES);
241+
return 0;
242+
}
243+
239244
if (len == 0)
240245
++len;
241246
if (strlength != NULL)
@@ -277,10 +282,18 @@ char *ossl_buf2hexstr_sep(const unsigned char *buf, long buflen, char sep)
277282
char *tmp;
278283
size_t tmp_n;
279284

285+
if (buflen < 0)
286+
return NULL;
280287
if (buflen == 0)
281288
return OPENSSL_zalloc(1);
282289

283-
tmp_n = (sep != CH_ZERO) ? buflen * 3 : 1 + buflen * 2;
290+
if ((sep != CH_ZERO && (size_t)buflen > SIZE_MAX / 3)
291+
|| (sep == CH_ZERO && (size_t)buflen > (SIZE_MAX - 1) / 2)) {
292+
ERR_raise(ERR_LIB_CRYPTO, CRYPTO_R_TOO_MANY_BYTES);
293+
return NULL;
294+
}
295+
296+
tmp_n = (sep != CH_ZERO) ? (size_t)buflen * 3 : 1 + (size_t)buflen * 2;
284297
if ((tmp = OPENSSL_malloc(tmp_n)) == NULL) {
285298
ERR_raise(ERR_LIB_CRYPTO, ERR_R_MALLOC_FAILURE);
286299
return NULL;

0 commit comments

Comments
 (0)