Conversation
wc_MlDsaKey_GetPrivLen(), wc_MlDsaKey_GetPubLen() and wc_MlDsaKey_GetSigLen() wrote through len without checking it. Return BAD_FUNC_ARG for a NULL len, as documented and as the LMS and XMSS getters do, and add NULL len cases to test_wc_MldsaDecisionCoverage().
|
Can one of the admins verify this patch? |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟢 Approval recommended
The implementation safely addresses the NULL dereference and includes focused regression tests.
Review effort: Balanced
Findings: None
What changed in this PR
Adds NULL-output-pointer validation to ML-DSA length getters, preventing invalid memory writes while honoring the documented API contract.
Changes:
- Return
BAD_FUNC_ARGwhenlenis NULL. - Add regression coverage for all three getters.
| File | Description |
|---|---|
wolfcrypt/src/wc_mldsa.c |
Validates len before writing and updates comments. |
tests/api/test_mldsa.c |
Tests NULL len handling. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
wc_MlDsaKey_GetPrivLen(), wc_MlDsaKey_GetPubLen() and wc_MlDsaKey_GetSigLen() write through len without checking it, so a NULL len is dereferenced. Their doxygen says they return BAD_FUNC_ARG when key or len is NULL, and the LMS and XMSS length getters already check len.
This adds the check to the three ML-DSA getters and updates their source comments. Nothing changes when len is a valid pointer, including the current behavior of storing the error code in *len when no parameter set is selected.
Testing
test_wc_MldsaDecisionCoverage() in tests/api/test_mldsa.c now calls each getter with a valid key and a NULL len, next to the existing NULL key cases. Without the wc_mldsa.c change, UBSan stops the test with a store to a null pointer in wc_MlDsaKey_GetPubLen(). With it, testwolfcrypt and the mldsa API group pass in this build and with --enable-mldsa=verify-only and the same flags. Tested on macOS (arm64) with Apple clang.
Checklist