Repository navigation
Reject PCR property capability counts larger than the response - #620
Conversation
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The parser now safely bounds attacker-controlled iteration and the targeted tests cover the reported failure modes.
Review effort: Balanced
Findings: None
What changed in this PR
Adds bounded parsing for PCR property capability responses, preventing oversized TPM-provided counts from causing excessive loops or fabricated entries.
Changes:
- Extracts PCR property parsing into a validated helper.
- Stops on packet exhaustion and returns
TPM_RC_SIZE. - Adds tests for valid, oversized, and truncated lists.
| File | Description |
|---|---|
src/tpm2.c |
Implements and integrates bounded PCR property parsing. |
wolftpm/tpm2_packet.h |
Declares the test-visible parser. |
tests/unit_tests.c |
Tests parser count handling and truncation. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
wolfSSL-Fenrir-bot
left a comment
There was a problem hiding this comment.
Fenrir Automated Review — PR #620
Scan targets checked: wolftpm-src, wolftpm-bugs
Coverage: 1 of 3 in-scope changed file(s) opened by the reviewer; not opened: tests/unit_tests.c, wolftpm/tpm2_packet.h
Fenrir result: Approved ✅
No new issues found in the changed files.
Advisory only — this automated result does not count as a GitHub approval.
Review tier: Lite
d5df124 to
20c271f
Compare
count could keep the CPU busy for seconds, or return 127 entries that were never sent.
match what was sent.
Reported by Vishnu Ajith @Vishnu2707
ZD #22559