libkmipclient: Fix integer overflow with large value length

Limit the value_len to not be larger than INT_MAX, because later on
BIO_read() is called with value_len and it uses the int type for
length parameter and return value.

This check also prevents the 'value_len + 1' from overflow, because
value_len is a size_t and this accepts larger values than int (even
on 32 bit architectures).

Assisted-by: IBM Bob:2.0.0
Signed-off-by: Ingo Franzki <ifranzki@linux.ibm.com>
Reviewed-by: Finn Callies <fcallies@linux.ibm.com>
Signed-off-by: Jan Höppner <hoeppner@linux.ibm.com>
This commit is contained in:
Ingo Franzki
2026-06-30 13:33:11 +02:00
committed by Jan Höppner
parent 7d56dde24a
commit 3ea90a2258

View File

@@ -104,6 +104,11 @@ int kmip_decode_ttlv(BIO *bio, size_t *size, struct kmip_node **node,
case KMIP_TYPE_TEXT_STRING:
case KMIP_TYPE_BYTE_STRING:
value_len = n->length;
if (value_len > INT_MAX) {
rc = -EMSGSIZE;
goto out;
}
value = calloc(1, value_len + 1);
if (value == NULL) {
kmip_debug(debug, "calloc failed");