Repository navigation
Reject truncated or malformed ML-KEM encapsulation results - #621
Conversation
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #621
Scan targets checked: wolftpm-src, wolftpm-bugs
Coverage: 4 of 5 in-scope changed file(s) opened by the reviewer; not opened: wolftpm/tpm2_packet.h
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
There was a problem hiding this comment.
Note
Copilot was unable to run its full agentic suite in this review.
Copilot review overview
Review effort: Lite
Findings: 4
Open (4)
On parse failure you zeroout->sharedSecretbut only setout->ciphertext.size = 0without… · New This helper returnsBAD_FUNC_ARGon NULL inputs, but callers insrc/tpm2.cuse the return value… · NewMlKemCiphertextSize()returns 0 for unknown parameter sets, but the caller treats any mismatch as… · NewTPM2_Packet_ParseU16BufStrictis declared asWOLFTPM_TEST_API, but it is now used by production… · New
What changed in this PR
This PR introduces stricter parsing for UINT16-length-prefixed buffers (fail on oversize/truncation instead of truncating) and adds ML-KEM output size validation, along with a unit test for the new strict parser.
Changes:
- Added
TPM2_Packet_ParseU16BufStrict()API and unit tests to enforce non-truncating parsing behavior. - Updated
TPM2_Encapsulate/TPM2_Decapsulateresponse parsing to use strict parsing and sanitize outputs on parse failure. - Added ML-KEM ciphertext/shared-secret size validation in wrapper APIs.
| File | Description |
|---|---|
| wolftpm/tpm2_packet.h | Declares new strict parsing API. |
| src/tpm2_packet.c | Implements strict parsing helper for UINT16-prefixed buffers. |
| src/tpm2.c | Switches Encapsulate/Decapsulate response parsing to strict parsing + sanitization. |
| src/tpm2_wrap.c | Adds ML-KEM output size sanity checks post-TPM call. |
| tests/unit_tests.c | Adds unit test coverage for strict parsing helper. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
Session parameter boundaries and decapsulation ciphertext sizes are not fully validated.
Review effort: Balanced
Findings: 1
Resolved since last review (4)
TPM2_Packet_ParseU16BufStrictis declared asWOLFTPM_TEST_API, but it is now used by production…MlKemCiphertextSize()returns 0 for unknown parameter sets, but the caller treats any mismatch as… This helper returnsBAD_FUNC_ARGon NULL inputs, but callers insrc/tpm2.cuse the return value… On parse failure you zeroout->sharedSecretbut only setout->ciphertext.size = 0without…


the bytes it actually received.
and clear the shared secret on failure.
ciphertext and a 32-byte shared secret.
Reported by Vishnu Ajith @Vishnu2707
ZD #225560