[openssl/openssl] 9fa890: CCM: authenticate empty Final when payload Update ...
"'Mounir IDRASSI' via openssl-commits" <[email protected]>
| Newsgroups | gmane.comp.encryption.openssl.cvs |
|---|---|
| Message-ID | <openssl/openssl/push/refs/heads/openssl-3.4/[email protected]> |
Branch: refs/heads/openssl-3.4
Home: https://github.com/openssl/openssl
Commit: 9fa890d55d49ea7062290450de83248b9cc3d0e0
https://github.com/openssl/openssl/commit/9fa890d55d49ea7062290450de83248b9cc3d0e0
Author: Mounir IDRASSI <[email protected]>
Date: 2026-08-21 (Fri, 21 Aug 2026)
Changed paths:
M providers/implementations/ciphers/ciphercommon_ccm.c
Log Message:
-----------
CCM: authenticate empty Final when payload Update is skipped
CCM Final was routed through an update helper whose pointer-based
dispatch treats a NULL-input call as a no-op or a length declaration.
If an empty message skips payload Update, decryption can therefore skip
tag verification and encryption does not generate a tag.
Process an empty payload during Final only when the existing state flags
show that no payload operation took place. Route the NULL-input
EVP_Cipher() form through the same Final path.
Fixes #32253
Assisted-by: Codex:gpt-5.6-sol
(cherry picked from commit 493a46c61983195c2b49bfde75ffba0321e5e69d)
Reviewed-by: Milan Broz <[email protected]>
Reviewed-by: Tomas Mraz <[email protected]>
Reviewed-by: Nikola Pajkovsky <[email protected]>
Merge-date: Fri Aug 21 10:00:11 2026
Merged-from: https://github.com/openssl/openssl/pull/32427
Commit: 4aa0fb3a5a858adb139650c56899a5f19ea7a9eb
https://github.com/openssl/openssl/commit/4aa0fb3a5a858adb139650c56899a5f19ea7a9eb
Author: Mounir IDRASSI <[email protected]>
Date: 2026-08-21 (Fri, 21 Aug 2026)
Changed paths:
M test/evp_extra_test.c
Log Message:
-----------
test: cover CCM empty Final without a payload Update
Declare a zero payload length and supply AAD while deliberately omitting
the payload Update. Check that streaming and one-shot Final generate the
same tag, accept the correct tag, and reject a modified tag for every
available built-in CCM cipher.
Assisted-by: Codex:gpt-5.6-sol
Reviewed-by: Milan Broz <[email protected]>
Reviewed-by: Tomas Mraz <[email protected]>
Reviewed-by: Nikola Pajkovsky <[email protected]>
Merge-date: Fri Aug 21 10:00:13 2026
Merged-from: https://github.com/openssl/openssl/pull/32427
Compare: https://github.com/openssl/openssl/compare/b3bfef0063a1...4aa0fb3a5a85
To unsubscribe from these emails, change your notification settings at https://github.com/openssl/openssl/settings/notifications
--
You received this message because you are subscribed to the Google Groups "openssl-commits" group.
To unsubscribe from this group and stop receiving emails from it, send an email to [email protected].
To view this discussion visit https://groups.google.com/a/openssl.org/d/msgid/openssl-commits/openssl/openssl/push/refs/heads/openssl-3.4/b3bfef-4aa0fb%40github.com.