Skip to content

Reject PCR property capability counts larger than the response - #620

Merged
dgarske merged 2 commits into
wolfSSL:masterfrom
aidangarske:pcr-properties-count-bound
Oct 5, 2026
Merged

dgarske merged 2 commits into
wolfSSL:masterfrom
aidangarske:pcr-properties-count-bound

Conversation

@aidangarske

@aidangarske aidangarske commented Oct 5, 2026 •

Copy link
Copy Markdown
Member
  • TPM2_GetCapability with TPM_CAP_PCR_PROPERTIES looped over the count the TPM declared even after the response ran out. A bad
    count could keep the CPU busy for seconds, or return 127 entries that were never sent.
  • The parse moves into TPM2_ParsePcrProperties. It stops when the response is used up and returns TPM_RC_SIZE if the count doesn't
    match what was sent.
  • Adds a unit test covering a well-formed list, lists longer than the local array, and oversized counts.

Reported by Vishnu Ajith @Vishnu2707

ZD #22559

@aidangarske aidangarske self-assigned this Oct 5, 2026
Copilot AI balanced review requested due to automatic review settings October 5, 2026 20:54

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟢 Approval recommended

The parser now safely bounds attacker-controlled iteration and the targeted tests cover the reported failure modes.

Review effort: Balanced
Findings: None

What changed in this PR

Adds bounded parsing for PCR property capability responses, preventing oversized TPM-provided counts from causing excessive loops or fabricated entries.

Changes:

  • Extracts PCR property parsing into a validated helper.
  • Stops on packet exhaustion and returns TPM_RC_SIZE.
  • Adds tests for valid, oversized, and truncated lists.
File Description
src/​tpm2.c Implements and integrates bounded PCR property parsing.
wolftpm/​tpm2_packet.h Declares the test-visible parser.
tests/​unit_tests.c Tests parser count handling and truncation.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

@wolfSSL-Fenrir-bot wolfSSL-Fenrir-bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Fenrir Automated Review — PR #620

Scan targets checked: wolftpm-src, wolftpm-bugs
Coverage: 1 of 3 in-scope changed file(s) opened by the reviewer; not opened: tests/unit_tests.c, wolftpm/tpm2_packet.h

Fenrir result: Approved ✅

No new issues found in the changed files.

Advisory only — this automated result does not count as a GitHub approval.

Review tier: Lite

dgarske
dgarske previously approved these changes Oct 5, 2026
@dgarske
dgarske merged commit 9464c59 into wolfSSL:master Oct 5, 2026
229 checks passed
@aidangarske
aidangarske deleted the pcr-properties-count-bound branch October 5, 2026 23:55
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants