From db2d0fd5120e778175865e491288b76bcefd9134 Mon Sep 17 00:00:00 2001 From: yuhan6665 <1588741+yuhan6665@users.noreply.github.com> Date: Sun, 10 May 2026 22:21:09 -0400 Subject: [PATCH] crypto/tls: reject 0xFFFF AEAD ID in pickECHConfig From the previous call-site: git show 9eeb627:src/crypto/internal/hpke/hpke.go | grep -A 10 "var SupportedAEADs" git show 9eeb627 | grep -n -B 10 -A 5 "SupportedAEADs" Change-Id: I7afcd01d3cbffa00d5714642cb8c8278f0cff445 Reviewed-on: https://go-review.googlesource.com/c/go/+/769280 Reviewed-by: Daniel McCarney Auto-Submit: Neal Patel Commit-Queue: Neal Patel LUCI-TryBot-Result: golang-scoped@luci-project-accounts.iam.gserviceaccount.com Reviewed-by: Roland Shoemaker --- ech.go | 5 +++++ 1 file changed, 5 insertions(+) diff --git a/ech.go b/ech.go index c19ff76..d88a138 100644 --- a/ech.go +++ b/ech.go @@ -184,6 +184,11 @@ func pickECHConfig(list []EchConfig) (*EchConfig, hpke.PublicKey, hpke.KDF, hpke if err != nil { continue } + // 0xFFFF is an export-only AEAD that cannot seal/open, making + // it an invalid choice for encrypting ClientHelloInner. + if cs.AEADID == 0xFFFF { + continue + } aead, err := hpke.NewAEAD(cs.AEADID) if err != nil { continue