Skip to content

zeroize sensitive memory and validate public API inputs#10413

Open
JeremiahM37 wants to merge 7 commits intowolfSSL:masterfrom
JeremiahM37:fenrir-7
Open

zeroize sensitive memory and validate public API inputs#10413
JeremiahM37 wants to merge 7 commits intowolfSSL:masterfrom
JeremiahM37:fenrir-7

Conversation

@JeremiahM37
Copy link
Copy Markdown
Contributor

Fixes F-1553, F-1554, F-1555, F-1917, F-2213, F-3095, F-3096, F-3351, F-3353, F-3555, F-3593, F-3594, F-3595, F-3596, F-3597, F-3598, F-3599, F-3600.

  • srp: mp_forcezero on password verifier, private exponent, and verifier-derived intermediate; free hash on error path
  • pkcs7: ForceZero plaintext payload before free in EncodeEnvelopedData / EncodeEncryptedData / EncodeAuthEnvelopedData
  • eddsa: ForceZero orig_k after sign-time integrity check (ed25519, ed448)
  • curve25519: ForceZero blinding state (a, n_a, rz) on every exit
  • slhdsa: ForceZero addRnd after wc_SlhDsaKey_Sign / SignHash
  • random: ForceZero DRBG newV on Hash_df failure (SHA-256 + SHA-512 reseed)
  • rsa: ForceZero OAEP seed on padding error paths
  • evp: ForceZero HKDF IKM in PKEY_CTX_set1_hkdf_key rotation and PKEY_free
  • camellia: add wc_CamelliaFree to wipe key schedule
  • evp: correct SM4-CTR debug message (was "AES CTR")
  • compress: bound wc_DeCompressDynamic input/growth against INT_MAX
  • asn: reject negative/zero size in wc_PemToDer
  • tests: cover wc_PemToDer and wc_DeCompressDynamic input validation

@JeremiahM37 JeremiahM37 self-assigned this May 6, 2026
@JeremiahM37 JeremiahM37 force-pushed the fenrir-7 branch 2 times, most recently from 2396169 to 329ddea Compare May 6, 2026 16:19
Copy link
Copy Markdown

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #10413

Scan targets checked: wolfcrypt-bugs, wolfcrypt-src

No new issues found in the changed files. ✅

@github-actions
Copy link
Copy Markdown

github-actions Bot commented May 7, 2026

MemBrowse Memory Report

gcc-arm-cortex-m4-baremetal

@JeremiahM37
Copy link
Copy Markdown
Contributor Author

Jenkins retest this please

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants