mirror of
https://github.com/openembedded/meta-openembedded.git
synced 2026-07-27 07:57:27 +00:00
9a19b0f3cb
Details: https://nvd.nist.gov/vuln/detail/CVE-2025-66215 Backport the patches referenced by the PR[1] mentioned in the nvd. Dropped the formatting commit from the backport. [1] https://github.com/OpenSC/OpenSC/pull/3436 Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com> Signed-off-by: Anuj Mittal <anuj.mittal@oss.qualcomm.com>
63 lines
2.1 KiB
Diff
63 lines
2.1 KiB
Diff
From 665871f38aee0d52eba923783d4606becc7628d0 Mon Sep 17 00:00:00 2001
|
|
From: Frank Morgner <frankmorgner@gmail.com>
|
|
Date: Thu, 5 Jun 2025 14:04:35 +0200
|
|
Subject: [PATCH] oberthur: use SC_MAX_APDU_RESP_SIZE where possible
|
|
|
|
(cherry picked from commit 56bc5e9575965461d99a274be45d71c18ab6eae0)
|
|
|
|
CVE: CVE-2025-66215
|
|
Upstream-Status: Backport [https://github.com/OpenSC/OpenSC/commit/56bc5e9575965461d99a274be45d71c18ab6eae0]
|
|
Signed-off-by: Ankur Tyagi <ankur.tyagi85@gmail.com>
|
|
---
|
|
src/libopensc/card-oberthur.c | 10 +++++-----
|
|
1 file changed, 5 insertions(+), 5 deletions(-)
|
|
|
|
diff --git a/src/libopensc/card-oberthur.c b/src/libopensc/card-oberthur.c
|
|
index 3e7a7b6b9..159b84aed 100644
|
|
--- a/src/libopensc/card-oberthur.c
|
|
+++ b/src/libopensc/card-oberthur.c
|
|
@@ -1133,7 +1133,7 @@ auth_compute_signature(struct sc_card *card, const unsigned char *in, size_t ile
|
|
apdu.datalen = ilen;
|
|
apdu.data = in;
|
|
apdu.lc = ilen;
|
|
- apdu.le = MIN(olen, 256);
|
|
+ apdu.le = MIN(olen, SC_MAX_APDU_RESP_SIZE);
|
|
apdu.resp = resp;
|
|
apdu.resplen = SC_MAX_APDU_BUFFER_SIZE;
|
|
|
|
@@ -1180,14 +1180,14 @@ auth_decipher(struct sc_card *card, const unsigned char *in, size_t inlen,
|
|
}
|
|
|
|
_inlen = inlen;
|
|
- if (_inlen == 256) {
|
|
+ if (_inlen == SC_MAX_APDU_RESP_SIZE) {
|
|
apdu.cla |= 0x10;
|
|
apdu.data = in;
|
|
apdu.datalen = 8;
|
|
apdu.resp = resp;
|
|
apdu.resplen = SC_MAX_APDU_BUFFER_SIZE;
|
|
apdu.lc = 8;
|
|
- apdu.le = 256;
|
|
+ apdu.le = SC_MAX_APDU_RESP_SIZE;
|
|
|
|
rv = sc_transmit_apdu(card, &apdu);
|
|
sc_log(card->ctx, "rv %i", rv);
|
|
@@ -1504,7 +1504,7 @@ auth_read_component(struct sc_card *card, enum SC_CARDCTL_OBERTHUR_KEY_TYPE type
|
|
{
|
|
struct sc_apdu apdu;
|
|
int rv;
|
|
- unsigned char resp[256];
|
|
+ unsigned char resp[SC_MAX_APDU_RESP_SIZE];
|
|
|
|
LOG_FUNC_CALLED(card->ctx);
|
|
sc_log(card->ctx, "num %i, outlen %"SC_FORMAT_LEN_SIZE_T"u, type %i",
|
|
@@ -2160,7 +2160,7 @@ auth_read_binary(struct sc_card *card, unsigned int offset,
|
|
if (auth_current_ef->magic==SC_FILE_MAGIC &&
|
|
auth_current_ef->ef_structure == SC_CARDCTL_OBERTHUR_KEY_RSA_PUBLIC) {
|
|
int jj;
|
|
- unsigned char resp[256];
|
|
+ unsigned char resp[SC_MAX_APDU_RESP_SIZE];
|
|
size_t resp_len, out_len;
|
|
struct sc_pkcs15_pubkey_rsa key;
|
|
|