Commit f2d2440
committed
Fix Coverity (D)TLS fragmentation size checks
Add MAX_RECORD_SIZE-based bounds checks in SendHandshakeMsg and Dtls13SendFragmentedInternal to prevent negative/overflowed fragment sizes from reaching memcpy/BuildMessage/DtlsMsgPoolSave.1 parent e70e7cb commit f2d2440
2 files changed
+17
-7
lines changed| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
978 | 978 | | |
979 | 979 | | |
980 | 980 | | |
981 | | - | |
| 981 | + | |
| 982 | + | |
982 | 983 | | |
983 | 984 | | |
984 | 985 | | |
| |||
988 | 989 | | |
989 | 990 | | |
990 | 991 | | |
991 | | - | |
| 992 | + | |
| 993 | + | |
| 994 | + | |
| 995 | + | |
| 996 | + | |
| 997 | + | |
992 | 998 | | |
993 | 999 | | |
994 | 1000 | | |
995 | 1001 | | |
996 | 1002 | | |
997 | | - | |
998 | | - | |
999 | | - | |
1000 | | - | |
| 1003 | + | |
| 1004 | + | |
1001 | 1005 | | |
1002 | 1006 | | |
1003 | 1007 | | |
| |||
1041 | 1045 | | |
1042 | 1046 | | |
1043 | 1047 | | |
1044 | | - | |
| 1048 | + | |
1045 | 1049 | | |
1046 | 1050 | | |
1047 | 1051 | | |
| |||
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
10766 | 10766 | | |
10767 | 10767 | | |
10768 | 10768 | | |
| 10769 | + | |
| 10770 | + | |
10769 | 10771 | | |
10770 | 10772 | | |
10771 | 10773 | | |
| |||
10801 | 10803 | | |
10802 | 10804 | | |
10803 | 10805 | | |
| 10806 | + | |
| 10807 | + | |
10804 | 10808 | | |
10805 | 10809 | | |
10806 | 10810 | | |
| |||
10816 | 10820 | | |
10817 | 10821 | | |
10818 | 10822 | | |
| 10823 | + | |
| 10824 | + | |
10819 | 10825 | | |
10820 | 10826 | | |
10821 | 10827 | | |
| |||
0 commit comments