39917 Commits
Author SHA1 Message Date
007bsd d099e33e57 aes_wrap: prevent crash on update without a key
EVP_CipherInit_ex2 with a NULL key followed by EVP_CipherUpdate
on AES-WRAP/WRAP-PAD/WRAP-INV ciphers dereferenced an uninitialised
function pointer because aes_wrap_init installs ctx->block only
when a key is supplied. aes_wrap_cipher_internal had no guard
before dispatching.

Track key state in ctx->key_set, matching OCB/CCM/GCM/Poly1305,
and refuse update if no key has been installed.

Added a regression test covering AES-256-WRAP, AES-256-WRAP-PAD
and AES-256-WRAP-INV.

CLA: trivial

Fixes: ca392b2943 "Add aes_wrap cipher to providers"

Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
MergeDate: Wed Jun  3 11:52:05 2026
(Merged from https://github.com/openssl/openssl/pull/31292)
2026-06-03 13:51:57 +02:00
kovan 14d4dedc2a doc: Clarify SSL_CERT_DIR uses semicolon separator on Windows
The documentation for SSL_CERT_DIR stated that directories are
colon-separated, but on Windows the separator is semicolon.

Updated:
- openssl-rehash.pod.in: Added note about semicolon separator on Windows
- openssl-env.pod: Added note about multiple directories and Windows separator

Fixes: #27698

Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>

Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
MergeDate: Wed Jun  3 11:44:35 2026
(Merged from https://github.com/openssl/openssl/pull/29894)
2026-06-03 13:44:30 +02:00
Bob Beck 68c0321e90 Provide ASN1_STRING_new_not_owned()
This function provides the ability to construct an ASN1_STRING
containing data that is not owned by the constructed ASN1_STRING. The
resulting ASN1_STRING, when freed, will not free the data, and it is
the caller's resposibility to ensure that the data lives past the
lifetime of any returned ASN1_STRING.

Why? you may ask? Many places where ->data and ->length were used
directly in the past before the opaquification of ASN1_STRING were
for this purpose, whether used for actual static data, or to turn
bytes created by and in control of the caller into an ASN1_STRING
for temporary use as an input. This function makes this easier
to do without making copies.

The function deliberately does not allow the creation of a BIT_STRING
as this would require also always providing unused bits, which is
annoying and unnecessary for almost all potential use cases.

For: https://github.com/openssl/openssl/issues/29861
For: https://github.com/openssl/openssl/issues/30162

Reviewed-by: Neil Horman <nhorman@openssl.org>
Reviewed-by: Saša Nedvědický <sashan@openssl.org>
MergeDate: Wed Jun  3 11:42:49 2026
(Merged from https://github.com/openssl/openssl/pull/30964)
2026-06-03 13:41:32 +02:00
rootvector2 46b5165d44 quic: avoid one-byte over-read of conn close reason in copy_tcause
For a remote CONNECTION_CLOSE, src->reason points straight into the
received packet and holds exactly reason_len bytes with no guaranteed
trailing byte. copy_tcause() did OPENSSL_memdup(src->reason, l + 1),
reading one byte past the source. The +1 is only needed to make room
for the NUL written at r[l], so allocate l + 1 but copy only the l
valid bytes.

Fixes: 40c8c756c8 "QUIC APL/CHANNEL: Wire up connection closure reason"

Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Kurt Roeckx <kurt@roeckx.be>
MergeDate: Wed Jun  3 11:39:47 2026
(Merged from https://github.com/openssl/openssl/pull/31349)
2026-06-03 13:39:43 +02:00
Teddy Engel d056bc0118 Remove unused crl_dir setting from config files
The crl_dir setting in CA_default section is not used anywhere. Remove
it from the example config and test configs, update the VMSify-conf.pl
path conversion script to no longer reference it, and regenerate
openssl-vms.cnf.

Fixes #31103

CLA: trivial

Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Frederik Wedel-Heinen <fwh.openssl@gmail.com>
Reviewed-by: Daniel Kubec <kubec@openssl.foundation>
MergeDate: Wed Jun  3 11:37:02 2026
(Merged from https://github.com/openssl/openssl/pull/31215)
2026-06-03 13:36:56 +02:00
Jakub Zelenka 4dcf6d276d statem: fix missing fatal if valid_flags mfail in process cert req
It is a contract of tls process functions to trigger fatal error if they
fail. This is not being done in checking result of s->s3.tmp.valid_flags
allocation. If this happens, it triggers alert in read_state_machine()
for READ_STATE_BODY state that calls this process function. It calls
check_fatal() if MSG_PROCESS_ERROR is returned and the assert in it
fails because no error is triggered.

The fix just adds the fatal and also uses MSG_PROCESS_ERROR macro as
return value instead of hard coded 0.

Reviewed-by: Milan Broz <mbroz@openssl.org>
Reviewed-by: Paul Yang <paulyang.inf@gmail.com>
MergeDate: Wed Jun  3 11:33:33 2026
(Merged from https://github.com/openssl/openssl/pull/31338)
2026-06-03 13:33:29 +02:00
Abel Tom c97318e35e crypto/hpke/hpke_util: Fixes redundant mdname is valid check.
Removed the redundant `mdname` is not NULL check.

Fixes #31299

Reviewed-by: Milan Broz <mbroz@openssl.org>
Reviewed-by: Frederik Wedel-Heinen <fwh.openssl@gmail.com>
MergeDate: Wed Jun  3 11:30:09 2026
(Merged from https://github.com/openssl/openssl/pull/31321)
2026-06-03 13:30:02 +02:00
Norbert Pocs d23670f3af Fix broken hex data by reformatting
The clang format broke some data in hexadecimal format.  To make the tool
obedient, the trailing comma needs to be removed, then it interpretes
the data differently and therefore does not reformat it.  The format can
then be changed to the correct form.

Fixes: https://github.com/openssl/project/issues/1959

Signed-off-by: Norbert Pocs <norbertp@openssl.org>

Reviewed-by: Milan Broz <mbroz@openssl.org>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Wed Jun  3 07:46:14 2026
(Merged from https://github.com/openssl/openssl/pull/31350)
2026-06-03 09:46:03 +02:00
rootvector2 78dd798232 rsa_sig: reject short buffers in raw verify_recover
The md==NULL path of rsa_verify_recover passed the caller buffer to
RSA_public_decrypt without checking routsize, while the X9.31 and PKCS#1
paths already reject undersized output buffers. RSA_public_decrypt writes
up to RSA_size() bytes, so a short rout overflows. Validate routsize
against RSA_size() before the call.

Fixes: 6f4b766315 "PROV: add RSA signature implementation"

Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Paul Yang <paulyang.inf@gmail.com>
MergeDate: Tue Jun  2 11:55:00 2026
(Merged from https://github.com/openssl/openssl/pull/31340)
2026-06-02 13:54:53 +02:00
Cristian Yxen e29a7e027c doc: Add a missing comma in -traditional option explanation.
CLA: trivial

Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Paul Yang <paulyang.inf@gmail.com>
MergeDate: Tue Jun  2 11:48:05 2026
(Merged from https://github.com/openssl/openssl/pull/31342)
2026-06-02 13:48:01 +02:00
Anton Moryakov d4c900174c test: fix unreachable code in test_kdf_pbkdf2_large_output in evp_kdf_test.c
The condition `if (sizeof(len) > 32)` was intended to set `len` to
SIZE_MAX on platforms where size_t can hold values larger than 32 bits.
However, sizeof() returns the size in bytes, not bits. Since sizeof(size_t)
is typically 4 or 8 bytes on all current platforms, the condition was
always false, leaving len at 0 and skipping the large-output test.

This commit fixes the check by comparing SIZE_MAX directly against
0xFFFFFFFFU, which correctly detects whether size_t can represent
values exceeding 32-bit range. This ensures the test properly validates
PBKDF2 behavior when requested output length is excessively large.

Fixes: 1cae59d14b "Make KDFs fail if requesting a zero-length key."
Signed-off-by: Anton Moryakov <ant.v.moryakov@gmail.com>

Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Daniel Kubec <kubec@openssl.foundation>
MergeDate: Tue Jun  2 11:10:23 2026
(Merged from https://github.com/openssl/openssl/pull/31344)
2026-06-02 13:09:59 +02:00
Ingo Franzki 0a396bdd1c s390x: Selectively re-format s390xcap.c
The clang formatter made some code places unreadable.  Selectively revert
the formatting to how it was before the re-formatting, and mark those places
with '/* clang-format off */' so that it does not get reformatted again.

While at it, change it to use designated initializers allowed with C-99.

No functional change intended.

Resolves: https://github.com/openssl/openssl/issues/31247
Signed-off-by: Ingo Franzki <ifranzki@linux.ibm.com>

Reviewed-by: Milan Broz <mbroz@openssl.org>
Reviewed-by: Tim Hudson <tjh@openssl.org>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Mon Jun  1 07:49:58 2026
(Merged from https://github.com/openssl/openssl/pull/31263)
2026-06-01 09:49:19 +02:00
007bsd 07485b844a poly1305: prevent crash on final without a key
EVP_MAC_init with a NULL key followed by EVP_MAC_final on a
Poly1305 context crashed with a NULL function-pointer dispatch
because poly1305_init accepted the no-key case as success, and
poly1305_final had no guard before dispatching through the
uninitialised Poly1305 state.

Add a key_set field to struct poly1305_data_st (matching
OCB/CCM/GCM), set it in poly1305_setkey, and refuse init and
final if no key has been installed.

Added a regression test asserting EVP_MAC_init with a NULL key
returns 0.

##### Checklist
- [ ] documentation is added or updated
- [x] tests are added or updated

CLA: trivial

Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Mon Jun  1 07:35:02 2026
(Merged from https://github.com/openssl/openssl/pull/31298)
2026-06-01 09:34:47 +02:00
Jakub Zelenka b084b6ebbf quic: fix keyslot cctx leak by not checking EL state in teardown
el_teardown_keyslot() decided whether to free a keyslot by calling
ossl_qrl_enc_level_set_has_keyslot() against the EL's current state.
On error paths the state does not yet match the slots that were
provisioned, so the check returned 0 and the cctx and iv were leaked.

The fix drops the state check and rely on the existing cctx != NULL
check which is sufficient for all callers of el_teardown_keyslot().

Reviewed-by: Matt Caswell <matt@openssl.foundation>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Saša Nedvědický <sashan@openssl.org>
MergeDate: Mon Jun  1 07:32:33 2026
(Merged from https://github.com/openssl/openssl/pull/31323)
2026-06-01 09:32:30 +02:00
Ilya Maximets a6c06fa699 ktls: Fix invalid memory access on retry with moving write buffer
kTLS write is using application buffer always without a memory copy.
And it completely ignores SSL_MODE_ACCEPT_MOVING_WRITE_BUFFER as a
result.  If the user frees or re-uses the original buffer and retries
the send on SSL_ERROR_WANT_WRITE, the code will read and send the data
from the original already freed buffer sending whatever happens to be
in that memory now and corrupting the message, potentially crashing
the application as well.

Fix by making a copy if we can't send the whole thing right away and
the moving write buffer is configured.

This preserves the zero-copy semantics for the happy path and avoids
the invalid memory access and data corruption when retry is necessary.
The copy is done in the common code as it is hard to preserve the
zero-copy behavior otherwise.

Test is added that reproduces the issue.  It may be possible to modify
the existing kTLS test to conditionally enable the modes and do the
BIO swap, but it feels like the issue deserves a separate one.

The test doesn't rely on any specific cypher or TLS version, so only
one combination is checked, but it should be enough.

There is no TLS_BUFFER_set_len() and the original kTLS code never
sets it, so not setting it on the copy either for now.

Fixes: 50ec750567 "ssl: Linux TLS Tx Offload"
Fixes #21202

Assisted-by: claude-opus-4.6

Reviewed-by: Matt Caswell <matt@openssl.foundation>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Mon Jun  1 07:29:13 2026
(Merged from https://github.com/openssl/openssl/pull/31146)
2026-06-01 09:29:12 +02:00
Herman Semenoff b069590724 ssl: avoid integer overflow by casting sum terms to size_t and not the result
Avoid possible integer overflow:  instead of casting the sum to size_t,
each operand of the sum is cast to size_t before addition to avoid int
overflow.

Signed-off-by: Herman Semenoff <GermanAizek@yandex.ru>

Reviewed-by: Matt Caswell <matt@openssl.foundation>
Reviewed-by: Tom Cosgrove <tom.cosgrove@arm.com>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Mon Jun  1 07:24:21 2026
(Merged from https://github.com/openssl/openssl/pull/30972)
2026-06-01 09:21:24 +02:00
Herman Semenoff 4d3d952b6e crypto, ssl: fix printf formats according to param types
inttypes.h is also used for more accurate compatibility with all
platforms, as it is the more correct choice according to C standard.

Signed-off-by: Herman Semenoff <GermanAizek@yandex.ru>

Reviewed-by: Paul Dale <paul.dale@oracle.com>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Mon Jun  1 06:58:24 2026
(Merged from https://github.com/openssl/openssl/pull/30969)
2026-06-01 08:58:00 +02:00
Herman Semenoff 0642e44723 apps: fix printf formats according to param types
inttypes.h is also used for more accurate compatibility with all
platforms, as it is the more correct choice according to C standard.

Signed-off-by: Herman Semenoff <GermanAizek@yandex.ru>

Reviewed-by: Paul Dale <paul.dale@oracle.com>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Mon Jun  1 06:58:23 2026
(Merged from https://github.com/openssl/openssl/pull/30969)
2026-06-01 08:57:22 +02:00
Dr. David von Oheimb b91dfe382f ossl_store.pod: add reference to the 'org.openssl.winstore' scheme
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Mon Jun  1 04:57:22 2026
(Merged from https://github.com/openssl/openssl/pull/25683)
2026-06-01 06:57:07 +02:00
Dr. David von Oheimb 8fe6f240d6 SSL_CTX_set1_verify_cert_store.pod: extend list of SEE ALSO references
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Mon Jun  1 04:57:19 2026
(Merged from https://github.com/openssl/openssl/pull/25683)
2026-06-01 06:57:07 +02:00
Dr. David von Oheimb 2b5a525b6d doc/man3/*.pod: fix doc cert_store vs. chain_store/verify_store and PEM format
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Mon Jun  1 04:57:17 2026
(Merged from https://github.com/openssl/openssl/pull/25683)
2026-06-01 06:57:07 +02:00
Dr. David von Oheimb d260311c53 apps/*.c,doc/man1/*.pod.in: fix doc and error output of cert_store vs. chain_store/verify_store and PEM format
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Mon Jun  1 04:57:15 2026
(Merged from https://github.com/openssl/openssl/pull/25683)
2026-06-01 06:57:07 +02:00
Dr. David von Oheimb fc06875716 openssl-rehash.pod.in: fix details of the general description how input files are handled
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Mon Jun  1 04:57:12 2026
(Merged from https://github.com/openssl/openssl/pull/25683)
2026-06-01 06:57:07 +02:00
Dr. David von Oheimb 86c4c6b3c4 apps/rehash.c: reading cert/CRL from PEM file gets no more confused by any included private keys
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Mon Jun  1 04:57:09 2026
(Merged from https://github.com/openssl/openssl/pull/25683)
2026-06-01 06:57:07 +02:00
rootvector2 a21f77dbc9 crypto/evp: fix double free of tmp_keymgmt in sig/kem/asym init
Commit ecb4757b37 "crypto/evp/m_sigver.c: fix potential double free
on error path in do_sigver_init" has fixed double-free of tmp_keymgmt
in do_sigver_init() by setting it to NULL after EVP_KEYMGMT_free() call;
the same issue present in evp_kem_init(), evp_pkey_asym_cipher_init(),
and evp_pkey_signature_init().  Address it similarly, by setting
the pointers to NULL after *_free() calls.

Complements: ecb4757b37 "crypto/evp/m_sigver.c: fix potential double free on error path in do_sigver_init"
Fixes: 839ffdd11c "EVP: Allow a fallback for operations that work with an EVP_PKEY"
CLA: trivial

Reviewed-by: Kurt Roeckx <kurt@roeckx.be>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Sun May 31 11:03:15 2026
(Merged from https://github.com/openssl/openssl/pull/31312)
2026-05-31 12:55:17 +02:00
Jakub Zelenka 31d61a1ceb quic: fix handling of the first rxe mfail in qrx_process_pkt
When qrx_ensure_free_rxe() fails at the start of qrx_process_pkt() the
function returned 0 without advancing the PACKET cursor and, for the
first packet in the datagram, without setting first_dcid. The
qrx_process_datagram() loop then re-entered qrx_process_pkt() for the
same bytes with pkt_idx >= 1 and the sentinel first_dcid (id_len = 255),
tripping the assertion in qrx_validate_hdr_early() that asserts
first_dcid->id_len to be lower than QUIC_MAX_CONN_ID_LEN.

The fix goes to malformed label instead. The header has not been decoded
at this point so eop is NULL, which makes the malformed path discard the
rest of the datagram. This is because without an RXE we can process
neither this packet nor any that follow it. This also advances the
cursor and, when the failure is on the first packet, avoids leaving
first_dcid unset for the next iteration. It is consistent with the
other allocation-failure site in the function, which already routes
through malformed.

Reviewed-by: Matt Caswell <matt@openssl.foundation>
Reviewed-by: Saša Nedvědický <sashan@openssl.org>
MergeDate: Fri May 29 14:08:56 2026
(Merged from https://github.com/openssl/openssl/pull/31316)
2026-05-29 16:08:16 +02:00
Wolfgang Beck 0c11947183 test/stack_test.c: Change structure SS typedef into TST_SS
The original name of the structure SS collides with a define set in
a Solaris system header.

Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: Saša Nedvědický <sashan@openssl.org>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
MergeDate: Fri May 29 07:56:28 2026
(Merged from https://github.com/openssl/openssl/pull/31224)
2026-05-29 09:55:16 +02:00
yangxuqing dd59758d07 slh_dsa: Remove redundant cleanup to prevent double free
Since SLH_DSA_KEY is allocated with OPENSSL_zalloc, its members are
NULL-initialized. Removing the redundant slh_dsa_key_hash_cleanup()
inside the err path of slh_dsa_key_hash_init() prevents the
double free while allowing the outer ossl_slh_dsa_key_free() to
safely handle the cleanup.

CLA: trivial

Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
MergeDate: Fri May 29 07:45:46 2026
(Merged from https://github.com/openssl/openssl/pull/31274)
2026-05-29 09:45:35 +02:00
Richard Levitte d3b4e88f2d Refactor BN_mod() and BN_nnmod() arguments to match documentation
The documentation has this signature for that function:

    int BN_mod(BIGNUM *r, const BIGNUM *a, const BIGNUM *m, BN_CTX *ctx);
    int BN_nnmod(BIGNUM *r, const BIGNUM *a, const BIGNUM *m, BN_CTX *ctx);

The implementation, however, had this signature:

    #define BN_mod(rem, m, d, ctx) BN_div(NULL, (rem), (m), (d), (ctx))
    int BN_nnmod(BIGNUM *r, const BIGNUM *m, const BIGNUM *d, BN_CTX *ctx);

That pattern alone trips up anyone who associates 'm' with modulus, and
and finds themselves using BN_nnmod() incorrectly.

This change modifies the argument names to match documentation.

Reviewed-by: Matt Caswell <matt@openssl.foundation>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Igor Ustinov <igus@openssl.foundation>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Fri May 29 07:25:31 2026
(Merged from https://github.com/openssl/openssl/pull/31304)
2026-05-29 09:25:27 +02:00
Jakub Zelenka 50fa6d38b3 quic: delay el keyslot teardown after creation in setup
There is an issue for key update in TX path if any of the operation
fails during keyslot setup (e.g. due to memory failure), the cctx stays
set to NULL which results in failed assertion in qtx_encrypt_into_txe.

The fix splits the build and installation steps in
ossl_qrl_enc_level_set_key_update so the cctx teardown is done only
after the build is successful. The install is then non fallible so it
cannot end up with empty cctx.

Reviewed-by: Saša Nedvědický <sashan@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
MergeDate: Fri May 29 07:18:36 2026
(Merged from https://github.com/openssl/openssl/pull/31268)
2026-05-29 09:18:29 +02:00
Daniel Kubec 06deb63cbb Fixes: 8b6a8a42af "Add a CHANGES.md entry"
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Bob Beck <beck@openssl.org>
MergeDate: Thu May 28 14:30:56 2026
(Merged from https://github.com/openssl/openssl/pull/31301)
2026-05-28 16:30:53 +02:00
Nikola Pajkovsky 94fbc0254f crypto/aes/asm/asm-sha{1,256}-armv8.pl: add missing function alignment
clang-22 reported missing alignment on MacOS:

    ld: warning: arm64 function not 4-byte aligned: _asm_sha1_hmac_aescbc_dec from libcrypto.a(libcrypto-lib-aes-sha1-armv8.o)
    ld: warning: arm64 function not 4-byte aligned: _asm_sha256_hmac_aescbc_dec from libcrypto.a(libcrypto-lib-aes-sha256-armv8.o)

Add ".align 4" directives to the affected functions.

Signed-off-by: Nikola Pajkovsky <nikolap@openssl.org>

Reviewed-by: Saša Nedvědický <sashan@openssl.org>
Reviewed-by: Tom Cosgrove <tom.cosgrove@arm.com>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Thu May 28 08:31:59 2026
(Merged from https://github.com/openssl/openssl/pull/31284)
2026-05-28 10:19:38 +02:00
Eugene Syromiatnikov 081901267a doc/man7/ossl-guide-migration.pod: reword DESCRIPTION section a bit
Update the wording in the DESCRIPTION section, so it is no longer implied
that OpenSSL 3.0 is something new.

Signed-off-by: Eugene Syromiatnikov <esyr@openssl.org>

Reviewed-by: Frederik Wedel-Heinen <fwh.openssl@gmail.com>
Reviewed-by: Igor Ustinov <igus@openssl.foundation>
MergeDate: Thu May 28 07:36:05 2026
(Merged from https://github.com/openssl/openssl/pull/31265)
2026-05-28 09:35:59 +02:00
Jakub Zelenka 75e504782d Split mfail output into counting and injection subtests
Counting now always runs and is always checked, including when
hooks are not installed or skip-all is set. Only injection is
skipped in those cases.

Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Matt Caswell <matt@openssl.foundation>
MergeDate: Thu May 28 07:33:05 2026
(Merged from https://github.com/openssl/openssl/pull/31219)
2026-05-28 09:32:57 +02:00
Nikola Pajkovsky 91a934ff02 quic: make ch_cleanup() idempotent and simplify channel error path
ch_init() calls ch_cleanup() on its own failure, after which
port_make_channel() may still call ossl_quic_channel_free() (which calls
ch_cleanup() again). The second call double-freed fields such as
ch->qlog_title.

To handle this, ch_cleanup() now NULLs every owned pointer after its
free and clears the have_statm / have_qsm flags after their destructors,
making it safe to invoke twice on the same channel.

With ch_cleanup() idempotent, port_make_channel() no longer needs the
ch_cleaned flag and the bare OPENSSL_free(ch) branch: the error path
unconditionally calls ossl_quic_channel_free() regardless of whether
ch_init() succeeded, partially initialized the channel, or already ran
ch_cleanup() on itself.

Signed-off-by: Nikola Pajkovsky <nikolap@openssl.org>

Reviewed-by: Saša Nedvědický <sashan@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Matt Caswell <matt@openssl.foundation>
Reviewed-by: Norbert Pocs <norbertp@openssl.org>
MergeDate: Thu May 28 07:26:22 2026
(Merged from https://github.com/openssl/openssl/pull/31177)
2026-05-28 09:26:13 +02:00
Daniel Kubec 4e8593e7eb TLS: Verify session ID to prevent incorrect session resumption
When a TLS 1.2 session is resumed via an external server-side cache
SSL_CTX_sess_set_get_cb(), the session ID stored in an SSL_SESSION is assigned
by the server at the end of the original full handshake and never modified
afterwards. The client-supplied session ID in ClientHello is copied verbatim
from the session the client cached after that same handshake. If both sides
behaved correctly, the two values are guaranteed to be identical.

This commit adds an explicit comparison inside ssl_get_prev_session() between
the session ID the client offered in ClientHello and the session ID embedded in
the SSL_SESSION returned by the external cache. If they do not match, the cached
session is released and ssl_get_prev_session() returns as a cache miss, forcing
a full handshake. Catching the mismatch here ensures the server never sends a
ServerHello that claims resumption of a session ID it cannot legitimately echo.

A mismatch unambiguously indicates one of the following:

 - a corrupt cache entry
 - an external cache implementation that returned the wrong session
 - an active tampering attempt

In all three cases refusing resumption and falling back to a full handshake is
the correct response.

Signed-off-by: Daniel Kubec <kubec@openssl.foundation>

Reviewed-by: Matt Caswell <matt@openssl.foundation>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
MergeDate: Wed May 27 12:36:49 2026
(Merged from https://github.com/openssl/openssl/pull/30517)
2026-05-27 14:36:11 +02:00
Mayank Jangid a31d5fe8f7 test: skip verify_recover regression for FIPS
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
MergeDate: Wed May 27 11:46:44 2026
(Merged from https://github.com/openssl/openssl/pull/30917)
2026-05-27 13:46:03 +02:00
Mayank Jangid 318b46e66e test: use 2048-bit RSA key for FIPS verify_recover regression
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
MergeDate: Wed May 27 11:46:43 2026
(Merged from https://github.com/openssl/openssl/pull/30917)
2026-05-27 13:46:03 +02:00
Mayank Jangid 2d076cf98d test: add explicit FIPS verify_recover regression
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
MergeDate: Wed May 27 11:46:42 2026
(Merged from https://github.com/openssl/openssl/pull/30917)
2026-05-27 13:46:03 +02:00
Mayank Jangid 62fa2eec5c test: skip verify_recover regression with old FIPS providers
Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
MergeDate: Wed May 27 11:46:41 2026
(Merged from https://github.com/openssl/openssl/pull/30917)
2026-05-27 13:46:03 +02:00
Mayank Jangid ca519ad1d5 rsa_sig: reject short buffers in verify_recover
The RSA PKCS#1 verify-recover provider path did not validate routsize
before passing the caller buffer to ossl_rsa_verify().

The X9.31 verify-recover path already rejects undersized output buffers,
but the PKCS#1 path could proceed with too little output space and rely
on the lower layer to write the recovered digest.

Check the expected digest size before calling ossl_rsa_verify() and
return PROV_R_OUTPUT_BUFFER_TOO_SMALL when the caller-provided buffer is
too small.

Add a regression test that covers both successful recovery with a
properly sized buffer and failure with a 1-byte output buffer, while
also checking that the short buffer is left unchanged.

Co-authored-by: Kushal <72255307+Kushalkhemka@users.noreply.github.com>
Co-authored-by: Mayank <175295782+mayank-jangid-moon@users.noreply.github.com>

Reviewed-by: Dmitry Belyavskiy <beldmit@gmail.com>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
MergeDate: Wed May 27 11:46:40 2026
(Merged from https://github.com/openssl/openssl/pull/30917)
2026-05-27 13:46:03 +02:00
Bob Beck 1e6dbc7340 Convert use of artisinally made hand crafted integer types
to use the stdint.h ones.

Reviewed-by: Richard Levitte <levitte@openssl.org>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
MergeDate: Wed May 27 09:09:41 2026
(Merged from https://github.com/openssl/openssl/pull/31254)
2026-05-27 11:08:08 +02:00
Bob Beck 02b955279c use stdint in modes.h
Reviewed-by: Richard Levitte <levitte@openssl.org>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
MergeDate: Wed May 27 09:09:41 2026
(Merged from https://github.com/openssl/openssl/pull/31254)
2026-05-27 11:08:08 +02:00
olszomal 1a55cfecca doc: match provider-asym_cipher(7) prototypes with core_dispatch.h
Reviewed-by: Frederik Wedel-Heinen <fwh.openssl@gmail.com>
Reviewed-by: Paul Dale <paul.dale@oracle.com>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Wed May 27 07:17:21 2026
(Merged from https://github.com/openssl/openssl/pull/31289)
2026-05-27 09:17:17 +02:00
olszomal a419b61d53 doc: remove outdated signature_dupctx usage note
EVP_PKEY_CTX_dup() may use the provider signature dupctx callback
via EVP_DigestSignFinal() and EVP_DigestVerifyFinal().

Complements: 864b89ce49 "Move EVP_PKEY algorithm implementations into a union"

Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Paul Dale <paul.dale@oracle.com>
MergeDate: Wed May 27 07:06:01 2026
(Merged from https://github.com/openssl/openssl/pull/31290)
2026-05-27 09:05:50 +02:00
Daiki Ueno 41b3e51d52 doc: clarify resumption semantics with -anti_replay in s_server
Signed-off-by: Daiki Ueno <dueno@redhat.com>

Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Wed May 27 07:01:39 2026
(Merged from https://github.com/openssl/openssl/pull/31291)
2026-05-27 09:01:36 +02:00
yangxuqing ecb4757b37 crypto/evp/m_sigver.c: fix potential double free on error path in do_sigver_init
In do_sigver_init(), if the for loop proceeds to its second iteration
(iter = 2), the results from the first iteration (signature and
tmp_keymgmt) are explicitly freed at the beginning of the loop.
However, the pointers are not set to NULL after being freed.

If an error occurs subsequently during this second iteration (for
example, if evp_signature_fetch_from_prov() returns NULL, triggering a
goto notsupported), the control flow jumps to the generic cleanup block
at the end of the function. This cleanup block calls
EVP_KEYMGMT_free(tmp_keymgmt) again on the dangling pointer, resulting
in a double free.

This commit resolves the issue by explicitly nullifying these pointers
immediately after they are freed at the start of the loop iteration.

(Note: This issue was discussed with the OpenSSL Security Team, who
classified it as a regular bug due to lack of attacker control and
requested a public PR.)

Fixes: 839ffdd11c "EVP: Allow a fallback for operations that work with an EVP_PKEY"
CLA: trivial

Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Tue May 26 15:28:15 2026
(Merged from https://github.com/openssl/openssl/pull/31276)
2026-05-26 17:27:02 +02:00
Daniel Kubec d73ad5615c test/tls13tickettest.c: check SSL_TICKET_NO_DECRYPT path in tls_parse_ctos_psk()
Add a test that rotates ticket keys so that the previously issued ticket
can no longer be decrypted:  if session resumption fails
due to a NO_DECRYPT, it is expected to fall back to a full handshake,
and a new session ticket is issued.

Complements: 6115286fae "TLSv1.3: reissue session ticket after full handshake on ciphersuite mismatch"
References: https://github.com/openssl/openssl/pull/30626

Reviewed-by: Matt Caswell <matt@openssl.foundation>
Reviewed-by: Bob Beck <beck@openssl.org>
Reviewed-by: Viktor Dukhovni <viktor@openssl.org>
Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
MergeDate: Tue May 26 15:20:59 2026
(Merged from https://github.com/openssl/openssl/pull/31223)
2026-05-26 17:20:47 +02:00
Eugene Syromiatnikov 700e962aa0 crypto/cmp/cmp_genm.c: avoid strcat() in get_genm_itav()
There is no need to use strcat() there, as it concatenates into a string
that is used in a format string anyway.  Put the literal prefix
into the format string and avoid literal string copying.

Fixes: d477484d33 "CMP: add support for genm/genp messages with id-it-caCerts"
Signed-off-by: Eugene Syromiatnikov <esyr@openssl.org>

Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
Reviewed-by: Nikola Pajkovsky <nikolap@openssl.org>
Reviewed-by: Bob Beck <beck@openssl.org>
Reviewed-by: David von Oheimb <david.von.oheimb@siemens.com>
MergeDate: Tue May 26 14:54:19 2026
(Merged from https://github.com/openssl/openssl/pull/31230)
2026-05-26 16:54:12 +02:00
Daniel Kubec be27d28c61 CHANGES.md: mention tickets disabling on set SSL_OP_NO_TICKET|SSL_SESS_CACHE_OFF
Complements: e5a18924e2 "TLS1.3: Disable tickets when SSL_OP_NO_TICKET and SSL_SESS_CACHE_OFF are set."

Reviewed-by: Eugene Syromiatnikov <esyr@openssl.org>
Reviewed-by: Tomas Mraz <tomas@openssl.foundation>
MergeDate: Tue May 26 14:40:46 2026
(Merged from https://github.com/openssl/openssl/pull/31288)
2026-05-26 16:39:08 +02:00