Merge pull request #2556 from pobregat0/ls2-key-section-length

LeaseSet2: check declared key length before creating an encryptor
This commit is contained in:
orignal
2026-09-14 21:59:30 -04:00
committed by GitHub
2 changed files with 7 additions and 2 deletions
+1 -1
View File
@@ -181,7 +181,7 @@ namespace crypto
switch (type)
{
case i2p::data::CRYPTO_KEY_TYPE_ELGAMAL: return 256;
case i2p::data::CRYPTO_KEY_TYPE_ECIES_P256_SHA256_AES256CBC: return 32;
case i2p::data::CRYPTO_KEY_TYPE_ECIES_P256_SHA256_AES256CBC: return 64; // x and y, 32 bytes each
case i2p::data::CRYPTO_KEY_TYPE_ECIES_X25519_AEAD: return 32;
// ML-KEM hybrid
case i2p::data::CRYPTO_KEY_TYPE_ECIES_MLKEM512_X25519_AEAD:
+6 -1
View File
@@ -423,7 +423,12 @@ namespace data
if (keyType <= i2p::data::CRYPTO_KEY_TYPE_ECIES_X25519_AEAD) // skip PQ keys if not supported
#endif
{
if ((keyType == m_PreferredEncryptionType || !newEncryptor || keyType > newEncryptionType) &&
// encryptionKeyLen is the length the publisher declares, and it was
// checked against the buffer. The encryptor reads a length fixed by
// the key type instead, so a section declaring a short ElGamal key
// makes it read 256 bytes out of a few
if (encryptionKeyLen >= i2p::crypto::GetCryptoPublicKeyLen (keyType) &&
(keyType == m_PreferredEncryptionType || !newEncryptor || keyType > newEncryptionType) &&
(!dest || dest->SupportsEncryptionType (keyType)))
{
auto encryptor = i2p::data::IdentityEx::CreateEncryptor (keyType, buf + offset);