[openssl/openssl] 1edbbe: CCM: authenticate empty Final when payload Update ...

"'Mounir IDRASSI' via openssl-commits" <[email protected]>
Newsgroups gmane.comp.encryption.openssl.cvs
Message-ID <openssl/openssl/push/refs/heads/openssl-3.5/[email protected]>
  Branch: refs/heads/openssl-3.5
  Home:   https://github.com/openssl/openssl
  Commit: 1edbbe38105b37d816ffeb91988d65953518324d
      https://github.com/openssl/openssl/commit/1edbbe38105b37d816ffeb91988d65953518324d
  Author: Mounir IDRASSI <[email protected]>
  Date:   2026-08-21 (Fri, 21 Aug 2026)

  Changed paths:
    M providers/implementations/ciphers/ciphercommon_ccm.c

  Log Message:
  -----------
  CCM: authenticate empty Final when payload Update is skipped

CCM Final was routed through an update helper whose pointer-based
dispatch treats a NULL-input call as a no-op or a length declaration.
If an empty message skips payload Update, decryption can therefore skip
tag verification and encryption does not generate a tag.

Process an empty payload during Final only when the existing state flags
show that no payload operation took place. Route the NULL-input
EVP_Cipher() form through the same Final path.

Fixes #32253

Assisted-by: Codex:gpt-5.6-sol

(cherry picked from commit 493a46c61983195c2b49bfde75ffba0321e5e69d)
Reviewed-by: Milan Broz <[email protected]>
Reviewed-by: Tomas Mraz <[email protected]>
Reviewed-by: Nikola Pajkovsky <[email protected]>
Merge-date: Fri Aug 21 09:57:46 2026
Merged-from: https://github.com/openssl/openssl/pull/32427


  Commit: e44fbf2ca18146cbd4f4d71c6078c9738964ec12
      https://github.com/openssl/openssl/commit/e44fbf2ca18146cbd4f4d71c6078c9738964ec12
  Author: Mounir IDRASSI <[email protected]>
  Date:   2026-08-21 (Fri, 21 Aug 2026)

  Changed paths:
    M test/evp_extra_test.c

  Log Message:
  -----------
  test: cover CCM empty Final without a payload Update

Declare a zero payload length and supply AAD while deliberately omitting
the payload Update. Check that streaming and one-shot Final generate the
same tag, accept the correct tag, and reject a modified tag for every
available built-in CCM cipher.

Assisted-by: Codex:gpt-5.6-sol
Reviewed-by: Milan Broz <[email protected]>
Reviewed-by: Tomas Mraz <[email protected]>
Reviewed-by: Nikola Pajkovsky <[email protected]>
Merge-date: Fri Aug 21 09:57:47 2026
Merged-from: https://github.com/openssl/openssl/pull/32427


Compare: https://github.com/openssl/openssl/compare/9954679e9da1...e44fbf2ca181

To unsubscribe from these emails, change your notification settings at https://github.com/openssl/openssl/settings/notifications

-- 
You received this message because you are subscribed to the Google Groups "openssl-commits" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-commits/openssl/openssl/push/refs/heads/openssl-3.5/995467-e44fbf%40github.com.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.