Skip to content

Commit 94e7321

Browse files
Add paragraph on undefined behaviour
Add a note that we do aim to protect against undefined behaviour and undefined behaviour in certificate parsing is in scope. Signed-off-by: David Horstmann <[email protected]>
1 parent 7950e9f commit 94e7321

File tree

1 file changed

+5
-0
lines changed

1 file changed

+5
-0
lines changed

SECURITY.md

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -158,3 +158,8 @@ Similarly, CSRs are implicitly trusted by Mbed TLS to be standards-compliant.
158158
validation is performed separately to ensure that they are compliant to the
159159
relevant specifications. This makes Mbed TLS on its own unsuitable use in a
160160
Certificate Authority (CA).
161+
162+
However, Mbed TLS aims to protect against memory corruption and other
163+
undefined behavior when parsing certificates and CSRs. If a CSR or signed
164+
certificate causes undefined behavior when it is parsed by Mbed TLS, that
165+
is considered a security vulnerability.

0 commit comments

Comments
 (0)