summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorJoel Sing <jsing@cvs.openbsd.org>2020-05-11 18:08:12 +0000
committerJoel Sing <jsing@cvs.openbsd.org>2020-05-11 18:08:12 +0000
commitb7317fc58ff1ba18611bb7369bebfa3bdb04ac87 (patch)
tree4eaf7b8f5a64d605fc229b40e4ff1e18945e903f
parent3fcefa1311a7040558d291070ab3c9c5f1bb48e8 (diff)
Propagate record overflows to the record layer and alert.
ok beck@ tb@
-rw-r--r--lib/libssl/tls13_internal.h3
-rw-r--r--lib/libssl/tls13_record.c5
-rw-r--r--lib/libssl/tls13_record_layer.c6
3 files changed, 8 insertions, 6 deletions
diff --git a/lib/libssl/tls13_internal.h b/lib/libssl/tls13_internal.h
index d35610e179d..5ea09db8a0d 100644
--- a/lib/libssl/tls13_internal.h
+++ b/lib/libssl/tls13_internal.h
@@ -1,4 +1,4 @@
-/* $OpenBSD: tls13_internal.h,v 1.78 2020/05/11 18:03:51 jsing Exp $ */
+/* $OpenBSD: tls13_internal.h,v 1.79 2020/05/11 18:08:11 jsing Exp $ */
/*
* Copyright (c) 2018 Bob Beck <beck@openbsd.org>
* Copyright (c) 2018 Theo Buehler <tb@openbsd.org>
@@ -39,6 +39,7 @@ __BEGIN_HIDDEN_DECLS
#define TLS13_IO_WANT_RETRY -5 /* Retry the previous call immediately. */
#define TLS13_IO_USE_LEGACY -6
#define TLS13_IO_RECORD_VERSION -7
+#define TLS13_IO_RECORD_OVERFLOW -8
#define TLS13_ERR_VERIFY_FAILED 16
#define TLS13_ERR_HRR_FAILED 17
diff --git a/lib/libssl/tls13_record.c b/lib/libssl/tls13_record.c
index ca61a94ff1e..c856932b403 100644
--- a/lib/libssl/tls13_record.c
+++ b/lib/libssl/tls13_record.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: tls13_record.c,v 1.5 2020/05/11 18:03:51 jsing Exp $ */
+/* $OpenBSD: tls13_record.c,v 1.6 2020/05/11 18:08:11 jsing Exp $ */
/*
* Copyright (c) 2018, 2019 Joel Sing <jsing@openbsd.org>
*
@@ -145,11 +145,10 @@ tls13_record_recv(struct tls13_record *rec, tls13_read_cb wire_read,
if (!CBS_get_u16(&cbs, &rec_len))
return TLS13_IO_FAILURE;
- /* XXX - record overflow alert. */
if ((rec_version >> 8) != SSL3_VERSION_MAJOR)
return TLS13_IO_RECORD_VERSION;
if (rec_len > TLS13_RECORD_MAX_CIPHERTEXT_LEN)
- return TLS13_IO_FAILURE;
+ return TLS13_IO_RECORD_OVERFLOW;
rec->content_type = content_type;
rec->version = rec_version;
diff --git a/lib/libssl/tls13_record_layer.c b/lib/libssl/tls13_record_layer.c
index 8ca52d0b7fa..82a49ae4255 100644
--- a/lib/libssl/tls13_record_layer.c
+++ b/lib/libssl/tls13_record_layer.c
@@ -1,4 +1,4 @@
-/* $OpenBSD: tls13_record_layer.c,v 1.40 2020/05/11 18:03:51 jsing Exp $ */
+/* $OpenBSD: tls13_record_layer.c,v 1.41 2020/05/11 18:08:11 jsing Exp $ */
/*
* Copyright (c) 2018, 2019 Joel Sing <jsing@openbsd.org>
*
@@ -768,11 +768,13 @@ tls13_record_layer_read_record(struct tls13_record_layer *rl)
if ((rl->rrec = tls13_record_new()) == NULL)
goto err;
}
-
+
if ((ret = tls13_record_recv(rl->rrec, rl->cb.wire_read, rl->cb_arg)) <= 0) {
switch (ret) {
case TLS13_IO_RECORD_VERSION:
return tls13_send_alert(rl, SSL_AD_PROTOCOL_VERSION);
+ case TLS13_IO_RECORD_OVERFLOW:
+ return tls13_send_alert(rl, SSL_AD_RECORD_OVERFLOW);
}
return ret;
}