guard minimum length in sm2 decrypt and gost/dstu/desede/rc2 unwrap#2359
Open
rootvector2 wants to merge 1 commit into
Open
guard minimum length in sm2 decrypt and gost/dstu/desede/rc2 unwrap#2359rootvector2 wants to merge 1 commit into
rootvector2 wants to merge 1 commit into
Conversation
ligefeiBouncycastle
self-requested a review
July 23, 2026 04:25
Collaborator
|
Thank you for the PR, nice catch. A few days ago I had identified the same issue in SM2 and GOST28147, and your PR also covers DSTU7624, DESede and RC2, so this is a good opportunity to combine the fixes. I'll merge them together. |
Contributor
Author
|
sounds good, makes sense to combine them. thanks for picking it up. |
Contributor
Author
|
sounds good. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
SM2Engine.decryptand theGOST28147/DSTU7624/DESede/RC2key-wrapunwrapengines sized their output asnew byte[inLen - overhead]without first checkinginLencovers that overhead, so a short attacker-supplied ciphertext threwNegativeArraySizeException/ArrayIndexOutOfBoundsExceptioninstead of the declaredInvalidCipherTextException; found auditing these against the already-guardedIESEngine/RFC3394WrapEngine/RFC5649WrapEngineand adds the same minimum-length check.