Skip to content

fix: correct KEM output truncation and EVP_PKEY_paramgen double-free - #50

Merged
tofay merged 1 commit into
mainfrom
kem-output-truncation
Sep 27, 2026
Merged

tofay merged 1 commit into
mainfrom
kem-output-truncation

Conversation

@tofay

@tofay tofay commented Sep 27, 2026

Copy link
Copy Markdown
Owner

Two bug fixes in the KEM implementation:

  1. Truncation: encapsulate_to_vec and decapsulate_to_vec now truncate their output buffers to the actual written length. A short write would otherwise leave trailing zeros in the shared secret, which is a key agreement that silently disagrees with the peer.

  2. Double-free: from_encoded_public_key no longer passes a pre-allocated EVP_PKEY to EVP_PKEY_paramgen. The function frees the passed pointer on failure, leaving a dangling pointer that is then freed again on the error path. Now passes NULL and lets paramgen allocate.

@tofay
tofay force-pushed the kem-output-truncation branch 2 times, most recently from 41a87f0 to 24e83c7 Compare September 27, 2026 21:31
@codecov

codecov Bot commented Sep 27, 2026 •

Copy link
Copy Markdown

Codecov Report

❌ Patch coverage is 0% with 5 lines in your changes missing coverage. Please review.
✅ Project coverage is 81.32%. Comparing base (6fa403d) to head (d4bc793).
⚠️ Report is 1 commits behind head on main.

Files with missing lines Patch % Lines
src/openssl_internal/kem.rs 0.00% 5 Missing ⚠️
Additional details and impacted files
@@            Coverage Diff             @@
##             main      #50      +/-   ##
==========================================
- Coverage   81.49%   81.32%   -0.17%     
==========================================
  Files          21       21              
  Lines        1967     1971       +4     
==========================================
  Hits         1603     1603              
- Misses        364      368       +4     

☔ View full report in Codecov by Harness.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.

@tofay
tofay force-pushed the kem-output-truncation branch from 24e83c7 to a714bf6 Compare September 27, 2026 21:34
Two bug fixes in the KEM implementation:

1. Truncation: encapsulate_to_vec and decapsulate_to_vec now truncate
   their output buffers to the actual written length. A short write would
   otherwise leave trailing zeros in the shared secret, which is a key
   agreement that silently disagrees with the peer.

2. Double-free: from_encoded_public_key no longer passes a pre-allocated
   EVP_PKEY to EVP_PKEY_paramgen. The function frees the passed pointer on
   failure, leaving a dangling pointer that is then freed again on the
   error path. Now passes NULL and lets paramgen allocate.
@tofay
tofay force-pushed the kem-output-truncation branch from a714bf6 to d4bc793 Compare September 27, 2026 21:38
@tofay
tofay marked this pull request as ready for review September 27, 2026 21:43
@tofay
tofay merged commit 9a67bff into main Sep 27, 2026
7 of 9 checks passed
@tofay
tofay deleted the kem-output-truncation branch September 27, 2026 21:43
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant