Skip to content

Commit d2ca86b

Browse files
nhormant8m
authored andcommitted
Reject potentially forged encrypted CMS AuthEnvelopedData messages
1. Adjust ossl_cms_EncryptedContent_init_bio to not accept non-AEAD ciphers. If a forged CMS message with AuthEnvelopedData is received with a non-AEAD cipher specified, we silently accept that and decrypt the message, skipping any authentication, which violates RFC 5083. We also add checks to ensure we fail if we try to encrypt AuthEnvelopedData without using an AEAD cipher. 2. Ensure that tag lengths on cms AEAD data is the recommended size. RFC 5084 recommends that mac tags be at least 12 bytes for AES-GCM and 4 bytes for AES-CCM on AuthEnvelopedData. As this code is not algorith-specific we add a check for a minimal size and just use the lower limit which is sufficient to prevent this attack. Without this check, its possible to set the tag length to 1 and within 256 guesses, forge a CMS message. Fixes CVE-2026-34182 Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org> Reviewed-by: Tomas Mraz <tomas@openssl.foundation> MergeDate: Mon Jun 8 14:29:56 2026
1 parent 316dfe1 commit d2ca86b

2 files changed

Lines changed: 8 additions & 6 deletions

File tree

‎crypto/cms/cms_enc.c‎

Lines changed: 7 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@
2323
/* Return BIO based on EncryptedContentInfo and key */
2424

2525
BIO *ossl_cms_EncryptedContent_init_bio(CMS_EncryptedContentInfo *ec,
26-
const CMS_CTX *cms_ctx, int auth)
26+
const CMS_CTX *cms_ctx, int auth)
2727
{
2828
BIO *b;
2929
EVP_CIPHER_CTX *ctx;
@@ -109,13 +109,15 @@ BIO *ossl_cms_EncryptedContent_init_bio(CMS_EncryptedContentInfo *ec,
109109
goto err;
110110
}
111111
piv = aparams.iv;
112-
if (ec->taglen > 0
113-
&& EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG,
114-
ec->taglen, ec->tag)
115-
<= 0) {
112+
113+
if (ec->taglen < 4 || ec->taglen > 16
114+
|| EVP_CIPHER_CTX_ctrl(ctx, EVP_CTRL_AEAD_SET_TAG, (int)ec->taglen, ec->tag) <= 0) {
116115
ERR_raise(ERR_LIB_CMS, CMS_R_CIPHER_AEAD_SET_TAG_ERROR);
117116
goto err;
118117
}
118+
} else if (auth) {
119+
ERR_raise(ERR_LIB_CMS, CMS_R_UNSUPPORTED_CONTENT_ENCRYPTION_ALGORITHM);
120+
goto err;
119121
}
120122
}
121123
len = EVP_CIPHER_CTX_get_key_length(ctx);

‎crypto/cms/cms_local.h‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -432,7 +432,7 @@ int ossl_cms_set1_ias(CMS_IssuerAndSerialNumber **pias, X509 *cert);
432432
int ossl_cms_set1_keyid(ASN1_OCTET_STRING **pkeyid, X509 *cert);
433433

434434
BIO *ossl_cms_EncryptedContent_init_bio(CMS_EncryptedContentInfo *ec,
435-
const CMS_CTX *ctx, int auth);
435+
const CMS_CTX *ctx, int auth);
436436
BIO *ossl_cms_EncryptedData_init_bio(const CMS_ContentInfo *cms);
437437
int ossl_cms_EncryptedContent_init(CMS_EncryptedContentInfo *ec,
438438
const EVP_CIPHER *cipher,

0 commit comments

Comments
 (0)