Skip to content

Reject truncated or malformed ML-KEM encapsulation results - #621

Merged
dgarske merged 3 commits into
wolfSSL:masterfrom
aidangarske:mlkem-encap-length-check
Oct 5, 2026
Merged

dgarske merged 3 commits into
wolfSSL:masterfrom
aidangarske:mlkem-encap-length-check

Conversation

@aidangarske

@aidangarske aidangarske commented Oct 5, 2026 •

Copy link
Copy Markdown
Member
  • TPM2_Encapsulate trimmed oversized lengths instead of rejecting them, and returned success with a ciphertext size larger than
    the bytes it actually received.
  • Adds TPM2_Packet_ParseU16BufStrict, which returns TPM_RC_SIZE instead of trimming. TPM2_Encapsulate and TPM2_Decapsulate use it
    and clear the shared secret on failure.
  • wolfTPM2_Encapsulate and wolfTPM2_Decapsulate now require the exact FIPS 203 sizes for ML-KEM keys: a 768, 1088 or 1568-byte
    ciphertext and a 32-byte shared secret.
  • Adds a unit test for the strict parser. The existing fwTPM ML-KEM encapsulate, decapsulate and round-trip tests still pass.

Reported by Vishnu Ajith @Vishnu2707

ZD #225560

@aidangarske aidangarske self-assigned this Oct 5, 2026
@aidangarske
aidangarske requested review from wolfSSL-Fenrir-bot and a balanced review from Copilot October 5, 2026 20:55

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #621

Scan targets checked: wolftpm-src, wolftpm-bugs
Coverage: 4 of 5 in-scope changed file(s) opened by the reviewer; not opened: wolftpm/tpm2_packet.h

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Note

Copilot was unable to run its full agentic suite in this review.

Copilot review overview

Review effort: Lite
Findings: 4 Medium severity

Open (4)
What changed in this PR

This PR introduces stricter parsing for UINT16-length-prefixed buffers (fail on oversize/truncation instead of truncating) and adds ML-KEM output size validation, along with a unit test for the new strict parser.

Changes:

  • Added TPM2_Packet_ParseU16BufStrict() API and unit tests to enforce non-truncating parsing behavior.
  • Updated TPM2_Encapsulate/TPM2_Decapsulate response parsing to use strict parsing and sanitize outputs on parse failure.
  • Added ML-KEM ciphertext/shared-secret size validation in wrapper APIs.
File Description
wolftpm/​tpm2_packet.h Declares new strict parsing API.
src/​tpm2_packet.c Implements strict parsing helper for UINT16-prefixed buffers.
src/​tpm2.c Switches Encapsulate/Decapsulate response parsing to strict parsing + sanitization.
src/​tpm2_wrap.c Adds ML-KEM output size sanity checks post-TPM call.
tests/​unit_tests.c Adds unit test coverage for strict parsing helper.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread src/tpm2.c
Comment thread src/tpm2_packet.c
Comment thread src/tpm2_wrap.c
Comment thread wolftpm/tpm2_packet.h

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Comment thread src/tpm2.c
@dgarske
dgarske merged commit 8328ea7 into wolfSSL:master Oct 5, 2026
230 checks passed
@aidangarske
aidangarske deleted the mlkem-encap-length-check branch October 5, 2026 22:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants