From 7dba75cce377f759f571d1187ea1e8f85b6a0b4b Mon Sep 17 00:00:00 2001 From: yuhan6665 <1588741+yuhan6665@users.noreply.github.com> Date: Thu, 10 Sep 2026 23:12:18 -0400 Subject: [PATCH] crypto/tls: omit PSK in ECH outer client hello When using ECH, do not include the PSK extension in the outer hello. Including the PSK extension allows for a degradation in privacy, as an on-path attacker can harvest outer client hellos, and then construct new hellos using the PSK extension and arbitrary guessed SNI values, replaying them to the target server. If the server rejects the PSK, the handshake will continue, but if the PSK is accepted, the binder check will fail. Thanks to Coia Prant (github.com/rbqvq) for reporting this issue. Fixes CVE-2026-42505 Fixes #79282 Change-Id: Ib3a3c948106a57c1b07b9e61a58cbf757848be18 Reviewed-on: https://go-review.googlesource.com/c/go/+/775960 Auto-Submit: Roland Shoemaker TryBot-Bypass: Roland Shoemaker Reviewed-by: Daniel McCarney Reviewed-by: Carlos Amedee --- handshake_messages.go | 4 +++- 1 file changed, 3 insertions(+), 1 deletion(-) diff --git a/handshake_messages.go b/handshake_messages.go index 3653035..610c857 100644 --- a/handshake_messages.go +++ b/handshake_messages.go @@ -5,6 +5,7 @@ package reality import ( + "bytes" "errors" "fmt" "slices" @@ -317,7 +318,8 @@ func (m *clientHelloMsg) marshalMsg(echInner bool) ([]byte, error) { }) }) } - if len(m.pskIdentities) > 0 { // pre_shared_key must be the last extension + // pre_shared_key must be the last extension + if len(m.pskIdentities) > 0 && (echInner || len(m.encryptedClientHello) == 0 || bytes.Equal(m.encryptedClientHello, []byte{byte(innerECHExt)})) { // RFC 8446, Section 4.2.11 exts.AddUint16(extensionPreSharedKey) exts.AddUint16LengthPrefixed(func(exts *cryptobyte.Builder) {