Skip to content

Conversation

@LinuxJedi
Copy link
Member

This includes:

  • Enforce TPM response HMAC length checks
  • Validate GetProductInfo payload length

Reject zero-length or mismatched response HMACs for authenticated sessions so forged SWTPM replies fail verification.
Reject undersized SWTPM responses before copying product info to avoid signed underflow and out-of-bounds access.
@dgarske dgarske merged commit 4a5c755 into wolfSSL:master Oct 22, 2025
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants