Closed Bug 2072389 Opened 16 days ago Closed 16 days ago

SECKEY_ConvertToPublicKey leaves a SECItem::type field uninitialized for EC keys

Categories

(NSS :: Libraries, defect, P2)

Tracking

(nss 3.130)

RESOLVED FIXED
Tracking Status
nss --- 3.130

People

(Reporter: jschanck, Assigned: jschanck)

References

(Regression)

Details

(Keywords: regression)

Attachments

(1 file)

In SECKEY_ConvertToPublicKey's ecKey path (lib/cryptohi/seckey.c):

  SECItem decodedPoint;                                  /* ~line 1861: uninitialized */
  ...
  rv = SEC_QuickDERDecodeItem(arena, &decodedPoint,
                              SEC_ASN1_GET(SEC_OctetStringTemplate), point);
  if (rv == SECSuccess) {
      *point = decodedPoint;                             /* copies garbage .type */
  }

NSS rarely inspects the type field of a SECItem, but nss-rs asserts that it is equal to siBuffer. This caused confusing intermittent failures in https://github.com/mozilla/nss-rs/pull/233.

Pushed by jschanck@mozilla.com:
https://hg.mozilla.org/projects/nss/rev/2a3747c91508
fix uninitialized SECItem.type in SECKEY_ConvertToPublicKey. r=nss-reviewers,keeler

Status: ASSIGNED → RESOLVED
Closed: 16 days ago
Resolution: --- → FIXED
status-nss: --- → 3.130
You need to log in before you can comment on or make changes to this bug.

Attachment

General

Created:
Updated:
Size: