mbedtls/library
Gilles Peskine 33d816aff9 Fix stack buffer overflow in net functions with large file descriptor
Fix a stack buffer overflow with mbedtls_net_recv_timeout() when given a
file descriptor that is beyond FD_SETSIZE. The bug was due to not checking
that the file descriptor is within the range of an fd_set object.

Fix #4169

Signed-off-by: Gilles Peskine <Gilles.Peskine@arm.com>
2021-03-03 12:23:27 +01:00
..
.gitignore
aes.c Put local variables in a struct 2020-10-22 10:34:20 +02:00
aesni.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
arc4.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
asn1parse.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
asn1write.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
base64.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
bignum.c mbedtls_mpi_sub_abs: fix buffer overflow in error case 2021-02-01 13:39:51 +01:00
blowfish.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
camellia.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
ccm.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
certs.c Update the copy of tests/data_files/server2-sha256.crt in certs.c 2020-08-24 15:15:00 +02:00
cipher_wrap.c Do not set IV size for ECB mode ciphers 2020-11-06 15:40:25 +01:00
cipher.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
cmac.c Fix mismatched function parameters (prototype/definition) 2020-11-29 08:09:58 -03:00
CMakeLists.txt Bump version to Mbed TLS 2.7.18 2020-12-09 01:22:11 +00:00
ctr_drbg.c Document mutex invariant for CTR_DRBG 2021-02-12 15:57:03 +01:00
debug.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
des.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
dhm.c Merge branch 'mbedtls-2.7' into mbedtls-2.7-restricted 2020-08-25 10:59:51 +02:00
ecdh.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
ecdsa.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
ecjpake.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
ecp_curves.c Fix uncaught error if fix_negative fails 2020-09-30 00:22:37 +02:00
ecp.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
entropy_poll.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
entropy.c Make entropy double-free work 2021-02-23 11:28:19 +01:00
error.c Simplify conditional guards in error.c 2020-11-16 16:09:41 +01:00
gcm.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
havege.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
hmac_drbg.c Document mutex invariant for HMAC_DRBG 2021-02-12 15:57:03 +01:00
Makefile Fix #2370, minor typos and spelling mistakes 2019-02-18 15:57:54 +00:00
md2.c Zeroize internal buffers and variables in MD hashes 2020-09-09 14:58:28 +02:00
md4.c Put local variables and buffers in a struct 2020-09-09 15:05:00 +02:00
md5.c Put local variables and buffers in a struct 2020-09-09 15:05:00 +02:00
md_wrap.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
md.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
memory_buffer_alloc.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
net_sockets.c Fix stack buffer overflow in net functions with large file descriptor 2021-03-03 12:23:27 +01:00
oid.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
padlock.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
pem.c Add tests for buffer corruption after PEM write 2020-12-07 16:49:30 +00:00
pk_wrap.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
pk.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
pkcs5.c Force cleanup before return 2020-09-09 14:51:03 +02:00
pkcs11.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
pkcs12.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
pkparse.c fix return code 2020-09-22 16:19:25 +02:00
pkwrite.c adding parentheses to macro definitions, to avoid confusion and possible mistakes in usage. 2021-02-01 18:53:22 +01:00
platform.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
ripemd160.c Put local variables and buffers in a struct 2020-09-09 15:05:00 +02:00
rsa_internal.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
rsa.c Fix mutex leak in RSA 2021-02-12 15:57:03 +01:00
sha1.c Put local variables and buffers in a struct 2020-09-09 15:05:00 +02:00
sha256.c Put local variables and buffers in a struct 2020-09-09 15:05:00 +02:00
sha512.c Put local variables and buffers in a struct 2020-09-09 15:05:00 +02:00
ssl_cache.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
ssl_ciphersuites.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
ssl_cli.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
ssl_cookie.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
ssl_srv.c Backport 2.7: Fix use of uinitialized memory in ssl_parse_encrypted_pms 2020-11-18 14:27:02 +01:00
ssl_ticket.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
ssl_tls.c Move declaration to fix C90 warning 2020-11-29 14:45:10 -03:00
threading.c Explain the usage of is_valid in pthread mutexes 2021-02-12 15:57:03 +01:00
timing.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
version_features.c Declare MBEDTLS_TEST_HOOKS in config.h 2021-01-29 19:08:23 +01:00
version.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
x509_create.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
x509_crl.c Merge branch 'mbedtls-2.7' into mbedtls-2.7-restricted 2020-08-25 10:59:51 +02:00
x509_crt.c Merge branch 'mbedtls-2.7-restricted' into mbedtls-2.7.18r0-pr 2020-12-08 21:00:50 +00:00
x509_csr.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
x509.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
x509write_crt.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
x509write_csr.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00
xtea.c Update copyright notices to use Linux Foundation guidance 2020-08-19 16:54:51 +02:00