mirror of
https://github.com/PurpleI2P/i2pd.git
synced 2026-10-06 07:48:00 +00:00
Merge pull request #2556 from pobregat0/ls2-key-section-length
LeaseSet2: check declared key length before creating an encryptor
This commit is contained in:
+1
-1
@@ -181,7 +181,7 @@ namespace crypto
|
||||
switch (type)
|
||||
{
|
||||
case i2p::data::CRYPTO_KEY_TYPE_ELGAMAL: return 256;
|
||||
case i2p::data::CRYPTO_KEY_TYPE_ECIES_P256_SHA256_AES256CBC: return 32;
|
||||
case i2p::data::CRYPTO_KEY_TYPE_ECIES_P256_SHA256_AES256CBC: return 64; // x and y, 32 bytes each
|
||||
case i2p::data::CRYPTO_KEY_TYPE_ECIES_X25519_AEAD: return 32;
|
||||
// ML-KEM hybrid
|
||||
case i2p::data::CRYPTO_KEY_TYPE_ECIES_MLKEM512_X25519_AEAD:
|
||||
|
||||
@@ -423,7 +423,12 @@ namespace data
|
||||
if (keyType <= i2p::data::CRYPTO_KEY_TYPE_ECIES_X25519_AEAD) // skip PQ keys if not supported
|
||||
#endif
|
||||
{
|
||||
if ((keyType == m_PreferredEncryptionType || !newEncryptor || keyType > newEncryptionType) &&
|
||||
// encryptionKeyLen is the length the publisher declares, and it was
|
||||
// checked against the buffer. The encryptor reads a length fixed by
|
||||
// the key type instead, so a section declaring a short ElGamal key
|
||||
// makes it read 256 bytes out of a few
|
||||
if (encryptionKeyLen >= i2p::crypto::GetCryptoPublicKeyLen (keyType) &&
|
||||
(keyType == m_PreferredEncryptionType || !newEncryptor || keyType > newEncryptionType) &&
|
||||
(!dest || dest->SupportsEncryptionType (keyType)))
|
||||
{
|
||||
auto encryptor = i2p::data::IdentityEx::CreateEncryptor (keyType, buf + offset);
|
||||
|
||||
Reference in New Issue
Block a user