libtasn1 | coding: rewrite _asn1_tag_der() to avoid the tag buffer overrun (#49) (!126)

Read-only notification of GnuTLS library development activities <[email protected]> Tue, 14 Jul 2026 16:33:23 +0000
Newsgroups gmane.comp.encryption.gpg.gnutls.devel
Message-ID <[email protected]>
--===============1297442738819015184==
Content-Type: multipart/alternative;
 boundary="--==_mimepart_6a5664d381165_3719c2b0481d0";
 charset=UTF-8
Content-Transfer-Encoding: 7bit


----==_mimepart_6a5664d381165_3719c2b0481d0
Content-Type: text/plain;
 charset=UTF-8
Content-Transfer-Encoding: quoted-printable



Thomas Grainger created a merge request: https://gitlab.com/gnutls/libtas=
n1/-/merge_requests/126

Project:Branches: graingert/libtasn1:fix-asn1-tag-der-overrun to gnutls/l=
ibtasn1:master
Author:   Thomas Grainger



Rewrites `_asn1_tag_der()` as a single pass that writes the tag number st=
raight to the output, most significant digit first, emitting at most `ASN=
1_MAX_TAG_SIZE - 1` continuation bytes. The result always fits in `ASN1_M=
AX_TAG_SIZE`, so the one-byte overrun in the old reverse-copy loop (issue=
 #49) is impossible by construction, as suggested by @jas in the issue.

The old truncation behaviour for over-long tags is preserved.

Adds `tests/Test_tag.c` covering:
* positive: `[APPLICATION 200000]` (needs the full three base-128 tag byt=
es) encodes to the known-good DER;
* negative: `[APPLICATION 2097152]` (a tag too large to encode) stays wit=
hin `ASN1_MAX_TAG_SIZE` =E2=80=94 before the rewrite this produced a nine=
-byte tag and AddressSanitizer reports a stack-buffer-overflow in `_asn1_=
tag_der`.

Closes #49

-- =

Reply to this email directly or view it on GitLab: https://gitlab.com/gnu=
tls/libtasn1/-/merge_requests/126
You're receiving this email because of your account on gitlab.com. Unsubs=
cribe from this thread: https://gitlab.com/-/namespace/17627195/sent_noti=
fications/5-conm8ohhq9fxo8uashu73jyfx-aht8b/unsubscribe | Manage all noti=
fications: https://gitlab.com/-/profile/notifications | Help: https://git=
lab.com/help



----==_mimepart_6a5664d381165_3719c2b0481d0
Content-Type: text/html;
 charset=UTF-8
Content-Transfer-Encoding: quoted-printable

<!DOCTYPE html PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN" "http://www=
.w3.org/TR/REC-html40/loose.dtd">
<html lang=3D"en" style=3D'--code-editor-font: var(--default-mono-font, "=
GitLab Mono"), JetBrains Mono, Menlo, DejaVu Sans Mono, Liberation Mono, =
Consolas, Ubuntu Mono, Courier New, andale mono, lucida console, monospac=
e;'>
<head>
<meta content=3D"text/html; charset=3Dutf-8" http-equiv=3D"Content-Type">=

<title>
GitLab
</title>

<style data-premailer=3D"ignore" type=3D"text/css">
a { color: #1068bf; }
</style>

<style>img {
max-width: 100%; height: auto;
}
body {
font-size: .875rem;
}
body {
-webkit-text-shadow: hsla(0,0%,100%,.01) 0 0 1px;
}
body {
font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"Segoe UI",Ro=
boto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif,"Apple Colo=
r Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji"; font-size=
: inherit;
}
</style>
</head>
<body style=3D'font-size: inherit; -webkit-text-shadow: hsla(0,0%,100%,.0=
1) 0 0 1px; font-family: "GitLab Sans",-apple-system,BlinkMacSystemFont,"=
Segoe UI",Roboto,"Noto Sans",Ubuntu,Cantarell,"Helvetica Neue",sans-serif=
,"Apple Color Emoji","Segoe UI Emoji","Segoe UI Symbol","Noto Color Emoji=
";'>
<div class=3D"content">

<p class=3D"details" style=3D"font-style: italic; color: #626168;">
<a href=3D"https://gitlab.com/graingert">Thomas Grainger</a> created a me=
rge request: <a href=3D"https://gitlab.com/gnutls/libtasn1/-/merge_reques=
ts/126">!126</a>
</p>
<div class=3D"branch">
Project:Branches: graingert/libtasn1:fix-asn1-tag-der-overrun to gnutls/l=
ibtasn1:master
</div>
<div class=3D"author">
Author: Thomas Grainger
</div>
<div class=3D"assignee">
Assignees: =

</div>
<div class=3D"reviewer">
Reviewers: =

</div>
<div class=3D"md gl-mt-5" style=3D"position: relative; z-index: 1; color:=
 #3a383f; word-wrap: break-word; margin-top: 1rem;">
<p dir=3D"auto" style=3D"color: #3a383f; margin: 0px 0px 1rem;" align=3D"=
initial">Rewrites <code style=3D'font-size: 90%; color: #18171d; word-wra=
p: break-word; background-color: #ececef; border-radius: .25rem; margin-t=
op: 0px; font-weight: inherit; overflow-wrap: break-word; white-space: br=
eak-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaV=
u Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New"=
, "andale mono", "lucida console", monospace; font-variant-ligatures: non=
e; word-break: keep-all; padding: 0.125rem 0.25rem;'>_asn1_tag_der()</cod=
e> as a single pass that writes the tag number straight to the output, mo=
st significant digit first, emitting at most <code style=3D'font-size: 90=
%; color: #18171d; word-wrap: break-word; background-color: #ececef; bord=
er-radius: .25rem; font-weight: inherit; overflow-wrap: break-word; white=
-space: break-spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menl=
o", "DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Co=
urier New", "andale mono", "lucida console", monospace; font-variant-liga=
tures: none; word-break: keep-all; padding: 0.125rem 0.25rem;'>ASN1_MAX_T=
AG_SIZE - 1</code> continuation bytes. The result always fits in <code st=
yle=3D'font-size: 90%; color: #18171d; word-wrap: break-word; background-=
color: #ececef; border-radius: .25rem; font-weight: inherit; overflow-wra=
p: break-word; white-space: break-spaces; font-family: "GitLab Mono", "Je=
tBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Consolas"=
, "Ubuntu Mono", "Courier New", "andale mono", "lucida console", monospac=
e; font-variant-ligatures: none; word-break: keep-all; padding: 0.125rem =
0.25rem;'>ASN1_MAX_TAG_SIZE</code>, so the one-byte overrun in the old re=
verse-copy loop (issue <a href=3D"https://gitlab.com/gnutls/libtasn1/-/wo=
rk_items/49" title=3D"Potential Buffer Overrun in _asn1_tag_der()" class=3D=
"gfm gfm-issue" data-original=3D"#49" data-link=3D"false" data-link-refer=
ence=3D"false" data-issue=3D"142675697" data-project=3D"919981" data-iid=3D=
"49" data-namespace-path=3D"gnutls/libtasn1" data-project-path=3D"gnutls/=
libtasn1" data-issue-type=3D"issue" data-container=3D"body" data-placemen=
t=3D"top" data-reference-type=3D"issue">#49</a>) is impossible by constru=
ction, as suggested by <a href=3D"https://gitlab.com/jas" title=3D"Simon =
Josefsson" class=3D"gfm gfm-project_member js-user-link" data-user=3D"472=
50" data-original=3D"@jas" data-container=3D"body" data-placement=3D"top"=
 data-reference-type=3D"user" style=3D"color: #284779; background-color: =
#cbe2f9; border-radius: .25rem; padding: 0 2px;">@jas</a> in the issue.</=
p>
<p dir=3D"auto" style=3D"color: #3a383f; margin: 0px 0px 1rem;" align=3D"=
initial">The old truncation behaviour for over-long tags is preserved.</p=
>
<p dir=3D"auto" style=3D"color: #3a383f; margin: 0px 0px 1rem;" align=3D"=
initial">Adds <code style=3D'font-size: 90%; color: #18171d; word-wrap: b=
reak-word; background-color: #ececef; border-radius: .25rem; margin-top: =
0px; font-weight: inherit; overflow-wrap: break-word; white-space: break-=
spaces; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sa=
ns Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "a=
ndale mono", "lucida console", monospace; font-variant-ligatures: none; w=
ord-break: keep-all; padding: 0.125rem 0.25rem;'>tests/Test_tag.c</code> =
covering:</p>
<ul dir=3D"auto" style=3D"text-align: initial; list-style-type: disc; mar=
gin: 0px 0px 1rem; padding: 0;">
<li style=3D"margin-top: 0px; line-height: 1.6em; margin-left: 25px; padd=
ing-left: 3px;">positive: <code style=3D'font-size: 90%; color: #18171d; =
word-wrap: break-word; background-color: #ececef; border-radius: .25rem; =
margin-top: 0px; font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "=
DejaVu Sans Mono", "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier=
 New", "andale mono", "lucida console", monospace; font-variant-ligatures=
: none; white-space: pre-wrap; overflow-wrap: break-word; word-break: kee=
p-all; padding: 0.125rem 0.25rem;'>[APPLICATION 200000]</code> (needs the=
 full three base-128 tag bytes) encodes to the known-good DER;</li>
<li style=3D"line-height: 1.6em; margin-left: 25px; padding-left: 3px;">n=
egative: <code style=3D'font-size: 90%; color: #18171d; word-wrap: break-=
word; background-color: #ececef; border-radius: .25rem; margin-top: 0px; =
font-family: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono"=
, "Liberation Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mo=
no", "lucida console", monospace; font-variant-ligatures: none; white-spa=
ce: pre-wrap; overflow-wrap: break-word; word-break: keep-all; padding: 0=
.125rem 0.25rem;'>[APPLICATION 2097152]</code> (a tag too large to encode=
) stays within <code style=3D'font-size: 90%; color: #18171d; word-wrap: =
break-word; background-color: #ececef; border-radius: .25rem; font-family=
: "GitLab Mono", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberati=
on Mono", "Consolas", "Ubuntu Mono", "Courier New", "andale mono", "lucid=
a console", monospace; font-variant-ligatures: none; white-space: pre-wra=
p; overflow-wrap: break-word; word-break: keep-all; padding: 0.125rem 0.2=
5rem;'>ASN1_MAX_TAG_SIZE</code> =E2=80=94 before the rewrite this produce=
d a nine-byte tag and AddressSanitizer reports a stack-buffer-overflow in=
 <code style=3D'font-size: 90%; color: #18171d; word-wrap: break-word; ba=
ckground-color: #ececef; border-radius: .25rem; font-family: "GitLab Mono=
", "JetBrains Mono", "Menlo", "DejaVu Sans Mono", "Liberation Mono", "Con=
solas", "Ubuntu Mono", "Courier New", "andale mono", "lucida console", mo=
nospace; font-variant-ligatures: none; white-space: pre-wrap; overflow-wr=
ap: break-word; word-break: keep-all; padding: 0.125rem 0.25rem;'>_asn1_t=
ag_der</code>.</li>
</ul>
<p dir=3D"auto" style=3D"color: #3a383f; margin: 0px;" align=3D"initial">=
Closes <a href=3D"https://gitlab.com/gnutls/libtasn1/-/work_items/49" tit=
le=3D"Potential Buffer Overrun in _asn1_tag_der()" class=3D"gfm gfm-issue=
" data-original=3D"#49" data-link=3D"false" data-link-reference=3D"false"=
 data-issue=3D"142675697" data-project=3D"919981" data-iid=3D"49" data-na=
mespace-path=3D"gnutls/libtasn1" data-project-path=3D"gnutls/libtasn1" da=
ta-issue-type=3D"issue" data-container=3D"body" data-placement=3D"top" da=
ta-reference-type=3D"issue" style=3D"margin-top: 0px;">#49</a></p>
</div>

</div>
<div class=3D"footer" style=3D"margin-top: 10px;">
<p style=3D"font-size: small; color: #626168;">
=E2=80=94
<br>
Reply to this email directly or <a href=3D"https://gitlab.com/gnutls/libt=
asn1/-/merge_requests/126">view it on GitLab</a>.
<br>
You're receiving this email because of your account on <a target=3D"_blan=
k" rel=3D"noopener noreferrer" href=3D"https://gitlab.com">gitlab.com</a>=
. <a href=3D"https://gitlab.com/-/namespace/17627195/sent_notifications/5=
-conm8ohhq9fxo8uashu73jyfx-aht8b/unsubscribe" target=3D"_blank" rel=3D"no=
opener noreferrer">Unsubscribe</a> from this thread =C2=B7 <a href=3D"htt=
ps://gitlab.com/-/profile/notifications" target=3D"_blank" rel=3D"noopene=
r noreferrer" class=3D"mng-notif-link">Manage all notifications</a> =C2=B7=
 <a href=3D"https://gitlab.com/help" target=3D"_blank" rel=3D"noopener no=
referrer" class=3D"help-link">Help</a>
<span style=3D"color: transparent; font-size: 0; display: none; overflow:=
 hidden; opacity: 0; width: 0; height: 0; max-width: 0; max-height: 0;">
Notification message regarding https://gitlab.com/gnutls/libtasn1/-/merge=
_requests/126 at 1784046803
</span>
<script type=3D"application/ld+json">{"@context":"http://schema.org","@ty=
pe":"EmailMessage","action":{"@type":"ViewAction","name":"View Merge requ=
est","url":"https://gitlab.com/gnutls/libtasn1/-/merge_requests/126"}}</s=
cript>


</p>
</div>
</body>
</html>

----==_mimepart_6a5664d381165_3719c2b0481d0--


--===============1297442738819015184==
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_______________________________________________
Gnutls-devel mailing list
[email protected]
http://lists.gnupg.org/mailman/listinfo/gnutls-devel

--===============1297442738819015184==--