VDB
Sign up
HIGH

GHSA-hppc-g8h3-xhp3

rust-openssl: Unchecked callback length in PSK/cookie trampolines leaks adjacent memory to peer

Details

The FFI trampolines behind `SslContextBuilder::set_psk_client_callback`, `set_psk_server_callback`, `set_cookie_generate_cb`, and `set_stateless_cookie_generate_cb` forwarded the user closure's returned usize directly to OpenSSL without checking it against the `&mut [u8]` that was handed to the closure. This can lead to buffer overflows and other unintended consequences.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/openssl
Introduced in: 0.9.24Fixed in: 0.10.78

Upgrade openssl to 0.10.78 or newer (ecosystem crates.io).

References