mirror of
https://github.com/XTLS/REALITY.git
synced 2026-09-28 01:48:07 +03:00
crypto/tls: reject 0xFFFF AEAD ID in pickECHConfig
From the previous call-site: git show 9eeb627:src/crypto/internal/hpke/hpke.go | grep -A 10 "var SupportedAEADs" git show 9eeb627 | grep -n -B 10 -A 5 "SupportedAEADs" Change-Id: I7afcd01d3cbffa00d5714642cb8c8278f0cff445 Reviewed-on: https://go-review.googlesource.com/c/go/+/769280 Reviewed-by: Daniel McCarney <daniel@binaryparadox.net> Auto-Submit: Neal Patel <nealpatel@google.com> Commit-Queue: Neal Patel <nealpatel@google.com> LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com <golang-scoped@luci-project-accounts.iam.gserviceaccount.com> Reviewed-by: Roland Shoemaker <roland@golang.org>
This commit is contained in:
@@ -184,6 +184,11 @@ func pickECHConfig(list []EchConfig) (*EchConfig, hpke.PublicKey, hpke.KDF, hpke
|
||||
if err != nil {
|
||||
continue
|
||||
}
|
||||
// 0xFFFF is an export-only AEAD that cannot seal/open, making
|
||||
// it an invalid choice for encrypting ClientHelloInner.
|
||||
if cs.AEADID == 0xFFFF {
|
||||
continue
|
||||
}
|
||||
aead, err := hpke.NewAEAD(cs.AEADID)
|
||||
if err != nil {
|
||||
continue
|
||||
|
||||
Reference in New Issue
Block a user