Skip to content

Fix out-of-bounds panic in ber2der on malformed BER input - #94

Merged
alexcottner merged 1 commit into
mozilla-services:masterfrom
hneiva:hneiva/berlen
Jul 21, 2026
Merged

Fix out-of-bounds panic in ber2der on malformed BER input#94
alexcottner merged 1 commit into
mozilla-services:masterfrom
hneiva:hneiva/berlen

Conversation

@hneiva

@hneiva hneiva commented Jul 21, 2026

Copy link
Copy Markdown

pkcs7.Parse() could panic with out-of-bounds slice/index reads when given certain tiny malformed BER inputs, instead of returning an error (CWE-125 / CWE-193). readObject() in ber.go guarded its cursor with offset > berLen rather than >=, letting offset reach berLen and still pass, so the subsequent ber[offset] read one past the end of the slice. The long-form length branch also sliced ber[offset:offset+numberOfBytes] with no upper-bound check.

  • Change the high-tag-number guards to offset >= berLen
  • Add an offset+numberOfBytes > berLen check before reading the long-form length octets.

Malformed inputs such as {1F 80}, {1F 05}, {30 81}, and {30 84 01} now return an error instead of panicking. Valid BER/DER, including empty definite-length objects and high-tag-number tags, is unaffected.

Add regression tests covering the malformed inputs (via ber2der and the exported Parse entry point) and a positive round-trip test for high-tag-number encodings.

`pkcs7.Parse()` could panic with out-of-bounds slice/index reads when given certain tiny malformed BER inputs, instead of returning an error (CWE-125 / CWE-193).
`readObject()` in ber.go guarded its cursor with `offset > berLen` rather than `>=`, letting `offset` reach `berLen` and still pass, so the subsequent `ber[offset]` read one past the end of the slice. The long-form length branch also sliced `ber[offset:offset+numberOfBytes]` with no upper-bound check.

- Change the high-tag-number guards to `offset >= berLen`
- Add an `offset+numberOfBytes > berLen` check before reading the long-form length octets.

Malformed inputs such as {1F 80}, {1F 05}, {30 81}, and {30 84 01} now return an error instead of panicking. Valid BER/DER, including empty definite-length objects and high-tag-number tags, is unaffected.

Add regression tests covering the malformed inputs (via ber2der and the exported `Parse` entry point) and a positive round-trip test for high-tag-number encodings.
@alexcottner
alexcottner merged commit 0b6e698 into mozilla-services:master Jul 21, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants