From cd92ddab44c45ed51bff5153cba3f0c55feac8e2 Mon Sep 17 00:00:00 2001 From: yuhan6665 <1588741+yuhan6665@users.noreply.github.com> Date: Thu, 10 Sep 2026 23:19:13 -0400 Subject: [PATCH] crypto/tls: avoid overflow in parseECHConfigList When parsing an ECHConfigList, length fields were previously evaluated as a uint16. This would cause an infinite loop to occur when parsing a 65532 bytes long ECHConfig with a declared outer length header of 0. MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit Triggering this condition requires a payload of at least 65538 bytes. As ECHConfigList payloads are typically delivered via protocols that limit them to 65535 bytes (DNS HTTPS records and TLS extensions), regular clients are safe from this issue. Thank you to Nguyễn Hoàng Hải (facebookmark2022@gmail.com) for reporting this issue. Fixes #80513 Change-Id: I8c5011d3b375c24794dd38b915bb4dc06a6a6964 Reviewed-on: https://go-review.googlesource.com/c/go/+/804040 Reviewed-by: Daniel McCarney Reviewed-by: Nicholas Husin LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com Reviewed-by: Roland Shoemaker --- ech.go | 6 +++--- 1 file changed, 3 insertions(+), 3 deletions(-) diff --git a/ech.go b/ech.go index 459803d..277eaaa 100644 --- a/ech.go +++ b/ech.go @@ -65,7 +65,7 @@ func parseECHConfig(enc []byte) (skip bool, ec EchConfig, err error) { if len(ec.raw) < int(ec.Length)+4 { return false, EchConfig{}, &echConfigErr{"length"} } - ec.raw = ec.raw[:ec.Length+4] + ec.raw = ec.raw[:int(ec.Length)+4] if ec.Version != extensionEncryptedClientHello { s.Skip(int(ec.Length)) return true, EchConfig{}, nil @@ -128,7 +128,7 @@ func parseECHConfigList(data []byte) ([]EchConfig, error) { if !s.ReadUint16(&length) { return nil, errMalformedECHConfigList } - if length != uint16(len(data)-2) { + if int(length) != len(data)-2 { return nil, errMalformedECHConfigList } var configs []EchConfig @@ -136,7 +136,7 @@ func parseECHConfigList(data []byte) ([]EchConfig, error) { if len(s) < 4 { return nil, errors.New("tls: malformed ECHConfig") } - configLen := uint16(s[2])<<8 | uint16(s[3]) + configLen := int(s[2])<<8 | int(s[3]) skip, ec, err := parseECHConfig(s) if err != nil { return nil, err